High severity8.5NVD Advisory· Published May 17, 2022· Updated Jun 17, 2026
CVE-2022-30945
CVE-2022-30945
Description
Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-cpsMaven | < 2692.v76b | 2692.v76b |
Affected products
3- cpe:2.3:a:jenkins:pipeline\:_groovy:*:*:*:*:*:jenkins:*:*Range: <2689.v434009a_31b_f1
- Range: unspecified
Patches
Vulnerability mechanics
References
6- www.jenkins.io/security/advisory/2022-05-17/nvdPatchVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2022/05/17/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-2xvx-rw9p-xgfcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-30945ghsaADVISORY
- github.com/jenkinsci/workflow-cps-plugin/commit/76a7681702f42d65f77bbaa5463f146876ea62dbghsaWEB
- github.com/jenkinsci/workflow-cps-plugin/commit/76b089ccd026b68012b0deb30c217395f7ca7dc2ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-05-17Jenkins Security Advisories · May 17, 2022