VYPR

Pipeline Groovy Libraries Plugin

by Jenkins Project

CVEs (2)

  • CVE-2026-48921HigMay 27, 2026
    risk 0.49cvss 7.5epss

    Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

  • CVE-2022-43405Oct 19, 2022
    risk 0.00cvss epss 0.00

    A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and…