Lucene search

K
nvd[email protected]NVD:CVE-2024-2216
HistoryMar 06, 2024 - 5:15 p.m.

CVE-2024-2216

2024-03-0617:15:11
web.nvd.nist.gov
1
cve-2024-2216
http endpoint
jenkins
docker-build-step
plugin
permission check
overall/read permission
tcp socket
unix socket
reconfigure
connection test
build step.

0.0004 Low

EPSS

Percentile

9.1%

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.

0.0004 Low

EPSS

Percentile

9.1%