QID 996871
Date Published: 2024-01-31
QID 996871: Java (Maven) Security Update for io.jenkins.plugins:gitlab-branch-source (GHSA-fw9h-cxx9-gfq3)
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fw9h-cxx9-gfq3 for updates and patch information.
Vendor References
- GHSA-fw9h-cxx9-gfq3 -
github.com/advisories/GHSA-fw9h-cxx9-gfq3
CVEs related to QID 996871
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fw9h-cxx9-gfq3 | io.jenkins.plugins:gitlab-branch-source |
|