« Volver al listado

CVE-2024-52550

Estado: AnalizadaAlta (8)—

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R y requiere interacción del usuario (rebuild) con acceso autenticado. Impacto: ejecución de código Groovy no aprobado en Jenkins; acceso/creación de cuentas de servicio mediante pipeline malicioso.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-52550",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-52550",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-13T21:27:04.283276Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins Project",
          "product": "Jenkins Pipeline: Groovy Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "maven",
              "lessThanOrEqual": "3975.v567e2a_1ffa_22"
            },
            {
              "status": "affected",
              "version": "3990.vd281dd77a_388"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:jenkins:groovy:*:*:*:*:*:jenkins:*:*"
          ],
          "vendor": "jenkins",
          "product": "groovy",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "3975.v567e2a_1ffa_22"
            },
            {
              "status": "affected",
              "version": "3990.vd281dd77a_388"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-13T21:15:29.293",
  "references": [
    {
      "url": "https://www.jenkins.io/security/advisory/2024-11-13/#SECURITY-3362",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-354"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved."
    },
    {
      "lang": "es",
      "value": "Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 y anteriores, excepto 3975.3977.v478dd9e956c3 no verifica si el script principal (Jenkinsfile) para una compilación reconstruida está aprobado, lo que permite a los atacantes con permiso de Elemento/Compilación reconstruir una compilación anterior cuyo script (Jenkinsfile) ya no está aprobado."
    }
  ],
  "lastModified": "2026-06-17T08:07:26.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:pipeline\\:_groovy:*:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16EA77F0-5CFE-46BD-BD6D-AB78137B3D2F",
              "versionEndExcluding": "3975.3977.v478dd9e956c3"
            },
            {
              "criteria": "cpe:2.3:a:jenkins:pipeline\\:_groovy:3990.vd281dd77a_388:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E8086C2-7557-44AE-8ABE-9FEB5EBFC7CF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}