Jenkins Project Jenkins Script Security Plugin vulnerabilities
29 known vulnerabilities affecting jenkins_project/jenkins_script_security_plugin.
Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH13MEDIUM8
Vulnerabilities
Page 2 of 2
CVE-2022-45379P3HIGHCVSS 7.5≥ unspecified, ≤ 1189.vb_a_b_7c8fd5fde2022-11-15
CVE-2022-45379 [HIGH] CWE-326 CVE-2022-45379: Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as th
Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
nvd
CVE-2019-10393P4MEDIUMCVSS 4.2v1.62 and earlier2019-09-12
CVE-2019-10393 [MEDIUM] CVE-2019-10393: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-10399P4MEDIUMCVSS 4.2v1.62 and earlier2019-09-12
CVE-2019-10399 [MEDIUM] CVE-2019-10399: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions in increment and decrement expressions allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-10400P4MEDIUMCVSS 4.2v1.62 and earlier2019-09-12
CVE-2019-10400 [MEDIUM] CVE-2019-10400: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-10394P4MEDIUMCVSS 4.2v1.62 and earlier2019-09-12
CVE-2019-10394 [MEDIUM] CVE-2019-10394: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2020-2190P4MEDIUMCVSS 5.4≥ unspecified, ≤ 1.722020-06-03
CVE-2020-2190 [MEDIUM] CWE-79 CVE-2020-2190: Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classp
Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.
nvd
CVE-2024-52549P4MEDIUMCVSS 4.3≤ 1362.v67dc1f0e1b_b_3v1365.v4778ca_84b_de5+1 more2024-11-13
CVE-2024-52549 [MEDIUM] CWE-862 CVE-2024-52549: Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ a
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
nvd
CVE-2026-42519P4MEDIUMCVSS 4.3≤ 1399.ve6a_66547f6e12026-04-29
CVE-2026-42519 [MEDIUM] CWE-862 CVE-2026-42519: A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
nvd
CVE-2022-30946P4MEDIUMCVSS 4.3≥ unspecified, ≤ 1158.v7c1b_73a_69a_082022-05-17
CVE-2022-30946 [MEDIUM] CWE-352 CVE-2022-30946: A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_6
A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.
nvd
← Previous2 / 2