8.8
CVE-2026-57301
- EPSS 0.43%
- Veröffentlicht 24.06.2026 13:20:16
- Zuletzt bearbeitet 26.06.2026 19:06:19
- Erkennungen
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Official Owasp Zap SwPlatform jenkins Version <= 1.0.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.35 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-610 Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3649