#VU85794 Improper access control in GitLab Branch Source - CVE-2024-23901
Published: January 25, 2024
GitLab Branch Source
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin unconditionally discovers projects that are shared with the configured owner group. A remote attacker can configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.