CVE-2024-52549
CVE-2024-52549 is a medium-severity vulnerability in Jenkins Script Security with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-3278
- Weakness: CWE-862
- Affected product: Jenkins Script Security
- Published:
- Last modified:
Description
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Frequently asked questions
- What is CVE-2024-52549?
- Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
- How severe is CVE-2024-52549?
- CVE-2024-52549 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2024-52549 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-52549?
- CVE-2024-52549 primarily affects Jenkins Script Security. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2024-52549?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-52549 have an EU (EUVD) identifier?
- Yes. CVE-2024-52549 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-3278.
- When was CVE-2024-52549 published?
- CVE-2024-52549 was published on 2024-11-13 and last updated on 2026-06-17.
References
Affected products (2)
- cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*
- cpe:2.3:a:jenkins:script_security:1365.v4778ca_84b_de5:*:*:*:*:jenkins:*:*
More vulnerabilities in Jenkins Script Security
- CVE-2022-43404 — Critical (CVSS 9.9): A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic…
- CVE-2022-43403 — Critical (CVSS 9.9): A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin…
- CVE-2022-43401 — Critical (CVSS 9.9): A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins…
- CVE-2020-2279 — Critical (CVSS 9.9): A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to…
- CVE-2019-10431 — Critical (CVSS 9.9): A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default…
- CVE-2019-1003029 — Critical (CVSS 9.9): A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in…
All CVEs affecting Jenkins Script Security →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-48168 — Critical (CVSS 10.0): PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is…
- CVE-2026-66012 — Critical (CVSS 10.0): SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated…
- CVE-2026-58275 — Critical (CVSS 10.0): Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-0092 — Critical (CVSS 10.0): In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could…
- CVE-2026-33712 — Critical (CVSS 10.0): Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST…
Browse all CWE-862 (Missing Authorization) vulnerabilities →