In Jenkins Bitbucket Branch Source Plugin 866.vdea7dcd3008e and earlier, except 848.850.v6aa2a234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.
{
"cpe": [
"cpe:2.3:a:jenkins:bitbucket_branch_source:*:*:*:*:*:jenkins:*:*",
"cpe:2.3:a:jenkins:bitbucket_branch_source:856.v04c46c86f911:*:*:*:*:jenkins:*:*",
"cpe:2.3:a:jenkins:bitbucket_branch_source:866.vdea_7dcd3008e:*:*:*:*:jenkins:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "848.850.v6a_a_2a_234a_c81"
},
{
"introduced": "856.v04c46c86f911"
},
{
"last_affected": "856.v04c46c86f911"
},
{
"introduced": "866.vdea_7dcd3008e"
},
{
"last_affected": "866.vdea_7dcd3008e"
}
]
}[
{
"digest": {
"length": 264.0,
"function_hash": "66523165340550917703522118877406842793"
},
"signature_version": "v1",
"source": "https://github.com/jenkinsci/bitbucket-branch-source-plugin/commit/6aa2a234ac81b6f4c6ca9ae6e465e4ff35dde071",
"signature_type": "Function",
"target": {
"function": "checkTrusted",
"file": "src/main/java/com/cloudbees/jenkins/plugins/bitbucket/ForkPullRequestDiscoveryTrait.java"
},
"id": "CVE-2024-28152-cc10ffda",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"30890580078752889672481009885636430360",
"229402029620681632373804298718475472446",
"256905793418602869343659903632231533641",
"212546324705304523228493246612319086967"
]
},
"signature_version": "v1",
"source": "https://github.com/jenkinsci/bitbucket-branch-source-plugin/commit/6aa2a234ac81b6f4c6ca9ae6e465e4ff35dde071",
"signature_type": "Line",
"target": {
"file": "src/main/java/com/cloudbees/jenkins/plugins/bitbucket/ForkPullRequestDiscoveryTrait.java"
},
"id": "CVE-2024-28152-f7826a9c",
"deprecated": false
}
]
"2026-07-09T14:44:10Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28152.json"