Loading HuntDB...

GHSA-p2qq-c693-q53w

GitHub Security Advisory

Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.

Affected Packages

Maven org.jenkinsci.plugins:pipeline-model-parent
Affected versions: 0 (fixed in 2.2218.v56d0cda)

Related CVEs

Key Information

GHSA ID
GHSA-p2qq-c693-q53w
Published
November 13, 2024 9:30 PM
Last Modified
November 14, 2024 3:43 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkinsci.plugins:pipeline-model-parent
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.