Description
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
References (5)
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
12.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-704
Status
published
Products (4)
jenkins/script_security
< 1.61
org.jenkins-ci.plugins/script-security
0 - 1.62Maven
redhat/openshift_container_platform
3.11
redhat/openshift_container_platform
4.1
Published
Jul 31, 2019
Tracked Since
Feb 18, 2026