CVE-2024-34148: Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
(updated )
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically sets the Java system property hudson.model.ParametersAction.keepUndefinedParameters
whenever a build is triggered from a release tag with the ‘Svn-Partial Release Manager’ SCM. Doing so disables the fix for SECURITY-170 / CVE-2016-3721.
As of publication of this advisory, there is no fix.
References
Detect and mitigate CVE-2024-34148 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →