Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.jenkins.plugins:gitlab-branch-source(Maven) | 0 | 688.v5fa | N/A |
CVSS Metrics