cbcvebase.
CVE-2017-1000107
published 2017-10-05

CVE-2017-1000107: Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider_plugin
jenkinscredentials_plugin
jenkinsdatadog_plugin
jenkinsdeploy_to_container_plugin
jenkinsdry_plugin
jenkinsgroovy_plugin
jenkinsinput_step_plugin
jenkinsowasp_dependency-check_plugin
jenkinsscript_security
jenkinsscript_security_plugin
jenkinsstatic_analysis_utilities_plugin
jenkinswarnings_plugin