Jenkins / Jenkins Script Security Plugin
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92129 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime… | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-92128 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and… | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-92127 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall… | HIGH | 8.0 | Sep 16, 2026 |
| CVE-2026-92126 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, al… | HIGH | 7.2 | Sep 16, 2026 |
| CVE-2026-92125 | org.jenkins-ci.plugins/script-security: Jenkins Script Security Plugin: Arbitrary code execution via Groovy AST transformation bypass | HIGH | 8.8 | Sep 16, 2026 |
| CVE-2026-92124 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a… | HIGH | 8.8 | Sep 16, 2026 |
| CVE-2026-92123 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribu… | HIGH | 8.8 | Sep 16, 2026 |
| CVE-2026-92122 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a v… | HIGH | 8.8 | Sep 16, 2026 |
| CVE-2026-84659 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbo… | MEDIUM | 4.3 | Sep 2, 2026 |
| CVE-2026-84658 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configur… | MEDIUM | 4.3 | Sep 2, 2026 |
| CVE-2026-57281 | jenkins-script-security-plugin: Jenkins Script Security Plugin: Arbitrary code execution outside sandbox | HIGH | 8.5 | Jun 24, 2026 |
| CVE-2026-57280 | jenkins-script-security-plugin: Jenkins Script Security Plugin: Sandbox bypass leading to arbitrary code execution | HIGH | 8.8 | Jun 24, 2026 |
| CVE-2026-42519 | Jenkins Script Security Plugin: Jenkins Script Security Plugin: Information disclosure via missing permission check | MEDIUM | 6.5 | Apr 29, 2026 |
| CVE-2024-52549 | jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability | MEDIUM | 4.3 | Nov 13, 2024 |
| CVE-2024-34145 | jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes | HIGH | 8.8 | May 2, 2024 |
| CVE-2024-34144 | jenkins-plugin/script-security: sandbox bypass via crafted constructor bodies | CRITICAL | 9.8 | May 2, 2024 |
| CVE-2023-24422 | jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin | HIGH | 8.8 | Jan 24, 2023 |
| CVE-2022-45379 | jenkins-plugin/script-security: Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions | HIGH | 8.0 | Nov 15, 2022 |
| CVE-2022-43404 | jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin | CRITICAL | 9.9 | Oct 19, 2022 |
| CVE-2022-43403 | jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin | CRITICAL | 9.9 | Oct 19, 2022 |
| CVE-2022-43401 | jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin | CRITICAL | 9.9 | Oct 19, 2022 |
| CVE-2022-30946 | plugin: CSRF vulnerability in Script Security Plugin | MEDIUM | 4.3 | May 17, 2022 |
| CVE-2020-2279 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide craft… | CRITICAL | 9.9 | Sep 23, 2020 |
| CVE-2020-2190 | jenkins-script-security-plugin: cross-site scripting vulnerability due to configure sandboxed scripts | MEDIUM | 5.4 | Jun 3, 2020 |
| CVE-2020-2135 | jenkins-script-security-plugin: sandbox protection bypass leads to arbitrary code execution | HIGH | 8.8 | Mar 9, 2020 |
Showing 1 to 25 of 39 CVEs