High severity8.8NVD Advisory· Published Nov 13, 2024· Updated Jun 17, 2026
CVE-2024-52554
CVE-2024-52554
Description
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.jenkins.plugins:shared-library-version-overrideMaven | < 19.v3a | 19.v3a |
Affected products
3- cpe:2.3:a:jenkins:shared_library_version_override:*:*:*:*:*:jenkins:*:*Range: <=17.v786074c9fce7
- Range: 0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-7845-crfj-phc4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-52554ghsaADVISORY
- www.jenkins.io/security/advisory/2024-11-13/nvdVendor AdvisoryWEB
News mentions
1- Jenkins Security Advisory 2024-11-13Jenkins Security Advisories · Nov 13, 2024