GHSA-p2qq-c693-q53w
GitHub Security Advisory
Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.
Affected Packages
Maven
org.jenkinsci.plugins:pipeline-model-parent
Affected versions:
0
(fixed in 2.2218.v56d0cda)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.