{ "id": "CVE-2024-28152", "sourceIdentifier": "jenkinsci-cert@googlegroups.com", "published": "2024-03-06T17:15:10.637", "lastModified": "2024-11-21T09:05:54.547", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy \"Forks in the same account\" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server." }, { "lang": "es", "value": "En el complemento Jenkins Bitbucket Branch Source 866.vdea_7dcd3008e y versiones anteriores, excepto 848.850.v6a_a_2a_234a_c81, al descubrir solicitudes de extracci\u00f3n de bifurcaciones, la pol\u00edtica de confianza \"Bifurcaciones en la misma cuenta\" permite cambios en los archivos Jenkins de usuarios sin acceso de escritura al proyecto cuando se usa Bitbucket Server. ." } ], "metrics": { "cvssMetricV31": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" }, "exploitabilityScore": 2.8, "impactScore": 3.4 } ] }, "weaknesses": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-281" } ] } ], "references": [ { "url": "http://www.openwall.com/lists/oss-security/2024/03/06/3", "source": "jenkinsci-cert@googlegroups.com" }, { "url": "https://www.jenkins.io/security/advisory/2024-03-06/#SECURITY-3300", "source": "jenkinsci-cert@googlegroups.com" }, { "url": "http://www.openwall.com/lists/oss-security/2024/03/06/3", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://www.jenkins.io/security/advisory/2024-03-06/#SECURITY-3300", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }