Description
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3OSVShared projects are unconditionally discovered by Jenkins GitLab Branch Source Plugin↗2024-01-24 ▶ CVEListCVE-2024-23901: Jenkins GitLab Branch Source Plugin 684↗2024-01-24 ▶ GHSAShared projects are unconditionally discovered by Jenkins GitLab Branch Source Plugin↗2024-01-24 ▶ 📋Vendor Advisories
2GitLabCVE-2024-23901: Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group↗2024-01-24 ▶ JenkinsJenkins Security Advisory 2024-01-24↗2024-01-24 ▶