Lucene search

K
vulnrichmentJenkinsVULNRICHMENT:CVE-2024-28159
HistoryMar 06, 2024 - 5:02 p.m.

CVE-2024-28159

2024-03-0617:02:00
jenkins
github.com
cve-2024-28159
jenkins
subversion
permission check
item/read
build trigger

AI Score

6.5

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:jenkins:subversion_partial_release_manager:1.0.1:*:*:*:*:jenkins:*:*"
    ],
    "vendor": "jenkins",
    "product": "subversion_partial_release_manager",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.1"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.5

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-28159