CVE-2024-28152
—CVSS 3.1
6.3 medium
EPSS
<1%p45
Published
()
Modified
Description
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.
- Vendors
- jenkins
- Products
- bitbucket branch source
- Weakness
- CWE-281
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.