Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-28152
HistoryMar 06, 2024 - 5:15 p.m.

Design/Logic Flaw

2024-03-0617:15:00
PRIOn knowledge base
www.prio-n.com
19
jenkins
bitbucket
branch source plugin
flaw
unauthorized changes
jenkinsfiles
forks
trust policy
bitbucket server

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy “Forks in the same account” allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%