Beveiligingsadvies

CVE-2024-28152

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-03-06 17:01:56
Laatst bijgewerkt 2025-02-13 17:47:19
Toegewezen door jenkins
CVSS-score 6.3
Status PUBLISHED

Beschrijving

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.