Loading HuntDB...

GHSA-7845-crfj-phc4

GitHub Security Advisory

Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection. This allows attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection. Shared Library Version Override Plugin 19.v3a_c975738d4a_ declares folder-scoped library overrides as untrusted, so that they’re executed in the Script Security sandbox.

Affected Packages

Maven io.jenkins.plugins:shared-library-version-override
Affected versions: 0 (fixed in 19.v3a)

Related CVEs

Key Information

GHSA ID
GHSA-7845-crfj-phc4
Published
November 13, 2024 9:30 PM
Last Modified
November 14, 2024 3:42 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins.plugins:shared-library-version-override
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.