cbcvebase.
CVE-2024-23901
published 2024-01-24

CVE-2024-23901: Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group…

PriorityP434medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.46%
36.8th percentile
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.

Affected

13 ranges
VendorProductVersion rangeFixed in
gitlabgitlab
jenkinsgit_server_plugin
jenkinsgithub_branch_source<= 684.vea_fa_7c1e2fe3
jenkinsgitlab_branch_source_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_uses_the_strict_crumb_issuer_plugin
jenkinsjenkins_weekly
jenkinslog_command_plugin
jenkinsmatrix_project_plugin
jenkinsqualys_policy_compliance_scanning_connector_plugin
jenkinsred_hat_dependency_analytics_plugin
jenkins_projectjenkins_gitlab_branch_source_plugin<= 684.vea_fa_7c1e2fe3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.