Severity
4.3MEDIUM
EPSS
0.3%
top 48.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13

Description

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_script_security_plugin1366.vd44b_49a_5c85c1367.vdf2fc45f229c+2
NVDjenkins/script_security1366.vd44b_49a_5c85c1367.vdf2fc45f229c+2

🔴Vulnerability Details

3
GHSA
Missing permission check in Jenkins Script Security Plugin2024-11-13
CVEList
CVE-2024-52549: Jenkins Script Security Plugin 13672024-11-13
OSV
Missing permission check in Jenkins Script Security Plugin2024-11-13

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2024-11-132024-11-13
Red Hat
jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability2024-11-13
CVE-2024-52549 (MEDIUM CVSS 4.3) | Jenkins Script Security Plugin 1367 | cvebase.io