CVE-2024-52550
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedJenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceThe Jenkins Pipeline: Groovy Plugin fails to re-validate script approval when rebuilding a previous build. Attackers with Item/Build permission can rebuild builds using Jenkinsfile scripts that were previously approved but subsequently revoked, bypassing the script approval sandbox.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 3975.3977.v478dd9e956c3= _groovyCVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Pipeline: Groovy Plugin versionNavigate to Manage Jenkins > Manage Plugins > Installed tab and search for 'Pipeline: Groovy' to see the installed version numberAffected if Version is lower than 3975.3977.v478dd9e956c3 or not visible (meaning it may be an older unpatched release)
-
Check if rebuild capability is in useReview recent build histories for entries showing 'Rebuild' action, or check if any jobs have the Rebuild plugin enabled in their configurationAffected if Rebuild has been used on any past builds containing Pipeline scripts
-
Review script approval historyGo to Manage Jenkins > In-process Script Approval and examine the approval status history. Look for scripts that show both 'Approved' and subsequently 'Revoked' or missing from the current approved listAffected if Any Jenkinsfile or Groovy scripts were previously approved but are now revoked or missing from the approved list
-
Check for unapproved scripts in rebuildable buildsExamine builds marked as 'Rebuilt' in build history and inspect what scripts they executed, comparing against current script approval statusAffected if A rebuilt build executed a script that is not currently in the approved list
Your environment is affected if you have Pipeline: Groovy Plugin version below 3975.3977.v478dd9e956c3 AND the Rebuild feature has been used on builds containing scripts that were approved but later revoked.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped3975.3977.v478dd9e956c3
Review and revoke unnecessary script approvals in Jenkins, disable or restrict the rebuild capability for builds using scripts that are no longer approved, and consider upgrading to a patched version once available.
Pipeline: Groovy Plugin version 3975.3977.v478dd9e956c3 or later
- Navigate to Manage Jenkins > Manage Plugins
- Go to the 'Installed' tab
- Locate the 'Pipeline: Groovy' plugin in the list
- If automatic updates are enabled, the plugin should auto-update to the fixed version
- Otherwise, check for available updates and apply them
- Restart Jenkins if required after plugin update
- Verify the fix by confirming that rebuilt builds now require Jenkinsfile script approval
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation4.0 h
- Testing3.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,088.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2024-52550 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2024-52550 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data