cbcvebase.

Jenkins Project Jenkins Script Security Plugin vulnerabilities

29 known vulnerabilities affecting jenkins_project/jenkins_script_security_plugin.

Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH13MEDIUM8

Vulnerabilities

Page 1 of 2
CVE-2019-1003029P1CRITICALCVSS 9.9KEVPoCv1.53 and earlier2019-03-08
CVE-2019-1003029 [CRITICAL] CVE-2019-1003029: A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the J
nvd
CVE-2019-1003005P2HIGHCVSS 8.8PoCv1.50 and earlier2019-02-06
CVE-2019-1003005 [HIGH] CVE-2019-1003005: A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
nvd
CVE-2024-34144P2CRITICALCVSS 9.8≤ 1335.vf07d9ce377a_e2024-05-02
CVE-2024-34144 [CRITICAL] CWE-693 CVE-2024-34144: A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugi A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
nvd
CVE-2022-43403P2CRITICALCVSS 9.9≥ unspecified, ≤ 1183.v774b_0b_0a_a_4512022-10-19
CVE-2022-43403 [CRITICAL] CVE-2022-43403: A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Scr A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
nvd
CVE-2022-43401P2CRITICALCVSS 9.9≥ unspecified, ≤ 1183.v774b_0b_0a_a_4512022-10-19
CVE-2022-43401 [CRITICAL] CVE-2022-43401: A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language r A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins
nvd
CVE-2020-2279P3CRITICALCVSS 9.9≥ unspecified, ≤ 1.742020-09-23
CVE-2020-2279 [CRITICAL] CVE-2020-2279: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers w A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.
nvd
CVE-2019-1003024P3HIGHCVSS 8.8v1.52 and earlier2019-02-20
CVE-2019-1003024 [HIGH] CVE-2019-1003024: A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectAS A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
nvd
CVE-2019-10431P3CRITICALCVSS 9.9v1.64 and earlier2019-10-01
CVE-2019-10431 [CRITICAL] CWE-94 CVE-2019-10431: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the han A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2022-43404P3CRITICALCVSS 9.9≥ unspecified, ≤ 1183.v774b_0b_0a_a_4512022-10-19
CVE-2022-43404 [CRITICAL] CVE-2022-43404: A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated s A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context
nvd
CVE-2024-34145P3HIGHCVSS 8.8≤ 1335.vf07d9ce377a_e2024-05-02
CVE-2024-34145 [HIGH] CWE-290 CVE-2024-34145: A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-de A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the
nvd
CVE-2026-57280P3HIGHCVSS 8.8≤ 1402.v94c9ce4648612026-06-24
CVE-2026-57280 [HIGH] CWE-693 CVE-2026-57280: Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type c Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
nvd
CVE-2019-1003040P3CRITICALCVSS 9.8v1.55 and earlier2019-03-28
CVE-2019-1003040 [CRITICAL] CWE-470 CVE-2019-1003040: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers t A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
nvd
CVE-2019-10356P3HIGHCVSS 8.8v1.61 and earlier2019-07-31
CVE-2019-10356 [HIGH] CVE-2019-10356: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the han A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-10355P3HIGHCVSS 8.8v1.61 and earlier2019-07-31
CVE-2019-10355 [HIGH] CWE-704 CVE-2019-10355: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the han A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-16538P3HIGHCVSS 8.8v1.67 and earlier2019-11-21
CVE-2019-16538 [HIGH] CWE-863 CVE-2019-16538: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the han A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2026-57281P3HIGHCVSS 7.5≤ 1402.v94c9ce4648612026-06-24
CVE-2026-57281 [HIGH] CWE-93 CVE-2026-57281: Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformat Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
nvd
CVE-2023-24422P3HIGHCVSS 8.8≥ unspecified, ≤ 1228.vd93135a_2fb_252023-01-26
CVE-2023-24422 [HIGH] CWE-78 CVE-2023-24422: A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd9 A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
nvd
CVE-2020-2110P3HIGHCVSS 8.8≥ unspecified, ≤ 1.692020-02-12
CVE-2020-2110 [HIGH] CWE-20 CVE-2020-2110: Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during t Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
nvd
CVE-2020-2134P3HIGHCVSS 8.8≥ unspecified, ≤ 1.702020-03-09
CVE-2020-2134 [HIGH] CWE-863 CVE-2020-2134: Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.
nvd
CVE-2020-2135P3HIGHCVSS 8.8≥ unspecified, ≤ 1.702020-03-09
CVE-2020-2135 [HIGH] CWE-863 CVE-2020-2135: Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
nvd
Jenkins Project Jenkins Script Security Plugin vulnerabilities | cvebase