CVE-2024-28152
06.03.2024, 17:15
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jenkins | bitbucket_branch_source | 𝑥 < 848.850.v6a_a_2a_234a_c81 |
| jenkins | bitbucket_branch_source | 856.v04c46c86f911:v04c46c86f911 |
| jenkins | bitbucket_branch_source | 866.vdea_7dcd3008e:vdea_7dcd3008e |
𝑥
= Vulnerable software versions
Common Weakness Enumeration