Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.

Project Subscriptions

Vendors Products
Jenkins Subscribe
Script Security Subscribe
Ocp Tools Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jv82-75fh-23r7 Missing permission check in Jenkins Script Security Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins script Security
CPEs cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:script_security:1365.v4778ca_84b_de5:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins script Security

Wed, 05 Mar 2025 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ocp Tools
CPEs cpe:/a:redhat:ocp_tools:4.12::el8
cpe:/a:redhat:ocp_tools:4.13::el8
cpe:/a:redhat:ocp_tools:4.14::el8
cpe:/a:redhat:ocp_tools:4.15::el8
cpe:/a:redhat:ocp_tools:4.16::el9
cpe:/a:redhat:ocp_tools:4.17::el9
Vendors & Products Redhat
Redhat ocp Tools

Fri, 22 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
Title jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 13 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
Description Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-11-13T21:35:30.700Z

Reserved: 2024-11-12T15:28:28.980Z

Link: CVE-2024-52549

cve-icon Vulnrichment

Updated: 2024-11-13T21:35:23.410Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-13T21:15:29.233

Modified: 2025-10-10T15:29:40.633

Link: CVE-2024-52549

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-13T20:53:00Z

Links: CVE-2024-52549 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses