SB2024111834 - Missing Authorization in Jenkins Shared Library Version Override plugin
Published: November 18, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authorization (CVE-ID: CVE-2024-52554)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to the script security bypass. A remote user can configure a folder-scoped library override that runs without sandbox protection.
Remediation
Install update from vendor's website.