{"schema_version":"1.7.3","id":"GHSA-p2qq-c693-q53w","published":"2024-11-13T21:30:38Z","modified":"2024-11-14T23:20:56.178332Z","aliases":["CVE-2024-52551"],"summary":"Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin ","details":"Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.\n","affected":[{"package":{"name":"org.jenkinsci.plugins:pipeline-model-parent","ecosystem":"Maven","purl":"pkg:maven/org.jenkinsci.plugins/pipeline-model-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2218.v56d0cda"}]}],"versions":["0.5","0.6","0.7","0.7.1","0.8","0.8.1","0.8.2","0.9","0.9.1","1.0","1.0.1","1.0.2","1.1","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2","1.2-beta-2","1.2-beta-3","1.2-beta-4","1.2-beta-5","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3","1.3.1","1.3.2","1.3.3","1.3.3.1","1.3.4","1.3.4.1","1.3.5","1.3.6","1.3.7","1.3.7-beta-1","1.3.8","1.3.9","1.4.0","1.4.0-beta1","1.4.0-beta3","1.4.0-beta4","1.4.0-beta5","1.5.0","1.5.0-beta1","1.5.0-rc1","1.5.1","1.6.0","1.7.0","1.7.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.9.0","1.9.1","1.9.2","1.9.3","2.2063.vb_1f41d1918e9","2.2064.v5eef7d0982b_e","2.2075.vce74e77b_ce40","2.2077.vc78ec45162f1","2.2081.v3919681ffc1e","2.2084.v1d2999534103","2.2086.v12b_420f036e5","2.2097.v33db_b_de764b_e","2.2114.v2654ca_721309","2.2118.v31fd5b_9944b_5","2.2121.vd87fb_6536d1e","2.2123.va_31cb_3b_80ef8","2.2125.vddb_a_44a_d605e","2.2131.vb_9788088fdb_5","2.2133.ve46a_6113dfc3","2.2141.v5402e818a_779","2.2144.v077a_d1928a_40","2.2150.v4cfd8916915c","2.2151.ve32c9d209a_3f","2.2168.vf921b_4e72c73","2.2169.vee7cd0efc13e","2.2175.v76a_fff0a_2618","2.2183.vb_36481468374","2.2184.v0b_358b_953e69","2.2188.v26e255fd2984","2.2198.v41dd8ef6dd56","2.2203.v89fa_170c2b_f5","2.2205.vc9522a_9d5711","2.2214.vb_b_34b_2ea_9b_83"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-p2qq-c693-q53w/GHSA-p2qq-c693-q53w.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52551"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/pipeline-model-definition-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2024-11-13/#SECURITY-3361"}],"database_specific":{"cwe_ids":["CWE-276","CWE-285"],"github_reviewed":true,"github_reviewed_at":"2024-11-14T15:43:58Z","nvd_published_at":"2024-11-13T21:15:29Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}