7.5

CVE-2016-3102

The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.

Data is provided by the National Vulnerability Database (NVD)
JenkinsScript Security Version1.0 SwPlatformjenkins
JenkinsScript Security Version1.1 SwPlatformjenkins
JenkinsScript Security Version1.2 SwPlatformjenkins
JenkinsScript Security Version1.3 SwPlatformjenkins
JenkinsScript Security Version1.4 SwPlatformjenkins
JenkinsScript Security Version1.5 SwPlatformjenkins
JenkinsScript Security Version1.6 SwPlatformjenkins
JenkinsScript Security Version1.7 SwPlatformjenkins
JenkinsScript Security Version1.8 SwPlatformjenkins
JenkinsScript Security Version1.9 SwPlatformjenkins
JenkinsScript Security Version1.10 SwPlatformjenkins
JenkinsScript Security Version1.11 SwPlatformjenkins
JenkinsScript Security Version1.12 SwPlatformjenkins
JenkinsScript Security Version1.13 SwPlatformjenkins
JenkinsScript Security Version1.14 SwPlatformjenkins
JenkinsScript Security Version1.15 SwPlatformjenkins
JenkinsScript Security Version1.16 SwPlatformjenkins
JenkinsScript Security Version1.17 SwPlatformjenkins
JenkinsScript Security Version1.18 SwPlatformjenkins
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.13
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.3 3.9 3.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P