CVE-2024-47804

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2024-10-02 16:15

Updated : 2025-03-14 16:15


NVD link : CVE-2024-47804

Mitre link : CVE-2024-47804

CVE.ORG link : CVE-2024-47804


JSON object : View

Products Affected

jenkins

  • jenkins
CWE
NVD-CWE-noinfo CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')