VYPR

Script Security

by Jenkins Project

Source repositories

CVEs (35)

  • CVE-2022-43404CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including…

  • CVE-2022-43403CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection…

  • CVE-2022-43401CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass…

  • CVE-2019-1003000HigJan 22, 2019
    risk 0.61cvss 8.8epss 0.98

    A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins…

  • CVE-2020-2279CriSep 23, 2020
    risk 0.58cvss 9.9epss 0.02

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.

  • CVE-2019-10431CriOct 1, 2019
    risk 0.58cvss 9.9epss 0.03

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2026-57280HigJun 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the…

  • CVE-2024-34145HigMay 2, 2024
    risk 0.57cvss 8.8epss 0.01

    A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to…

  • CVE-2019-10356HigJul 31, 2019
    risk 0.57cvss 8.8epss 0.03

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-1003040CriMar 28, 2019
    risk 0.57cvss 9.8epss 0.03

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.

  • CVE-2017-1000107HigOct 5, 2017
    risk 0.57cvss 8.8epss 0.01

    Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing…

  • CVE-2019-1003005HigFeb 6, 2019
    risk 0.55cvss 8.8epss 0.19

    A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint…

  • CVE-2023-24422HigJan 26, 2023
    risk 0.50cvss 8.8epss 0.01

    A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in…

  • CVE-2020-2135HigMar 9, 2020
    risk 0.50cvss 8.8epss 0.01

    Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

  • CVE-2020-2134HigMar 9, 2020
    risk 0.50cvss 8.8epss 0.01

    Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.

  • CVE-2020-2110HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

  • CVE-2019-16538HigNov 21, 2019
    risk 0.50cvss 8.8epss 0.01

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-10355HigJul 31, 2019
    risk 0.50cvss 8.8epss 0.03

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-1003024HigFeb 20, 2019
    risk 0.50cvss 8.8epss 0.03

    A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the…

  • CVE-2018-1000865HigDec 10, 2018
    risk 0.50cvss 8.8epss 0.02

    A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins…

Page 1 of 2