CVE-2024-23901 affects the Jenkins GitLab Branch Source Plugin (versions 684.vea_fa_7c1e2fe3 and earlier), allowing attackers to craft and share projects that Jenkins will automatically build during a group scan. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and can lead to unauthorized code execution (C:L/I:L), though it does not impact availability. There is currently no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal, indicating low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 684.vea_fa_7c1e2fe3CPE matchmatch criteria | cpe:2.3:a:jenkins:github_branch_source:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.