CVE-2026-92129
- EPSS 0.45%
- Veröffentlicht 16.09.2026 13:53:07
- Zuletzt bearbeitet 21.09.2026 17:15:00
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelin...
CVE-2026-92128
- EPSS 0.22%
- Veröffentlicht 16.09.2026 13:53:06
- Zuletzt bearbeitet 21.09.2026 17:16:03
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath...
- EPSS 0.47%
- Veröffentlicht 16.09.2026 13:53:06
- Zuletzt bearbeitet 21.09.2026 17:16:22
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API ...
CVE-2026-92126
- EPSS 0.2%
- Veröffentlicht 16.09.2026 13:53:05
- Zuletzt bearbeitet 27.09.2026 00:16:35
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, ...
CVE-2026-92125
- EPSS 0.51%
- Veröffentlicht 16.09.2026 13:53:05
- Zuletzt bearbeitet 21.09.2026 17:30:09
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transf...
CVE-2026-92124
- EPSS 0.59%
- Veröffentlicht 16.09.2026 13:53:04
- Zuletzt bearbeitet 21.09.2026 17:30:34
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allo...
CVE-2026-92123
- EPSS 0.59%
- Veröffentlicht 16.09.2026 13:53:03
- Zuletzt bearbeitet 21.09.2026 17:33:17
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sand...
CVE-2026-92122
- EPSS 0.61%
- Veröffentlicht 16.09.2026 13:53:03
- Zuletzt bearbeitet 21.09.2026 17:35:00
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface metho...
CVE-2026-84659
- EPSS 0.17%
- Veröffentlicht 02.09.2026 15:40:47
- Zuletzt bearbeitet 22.09.2026 13:24:19
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data bi...
CVE-2026-84658
- EPSS 0.19%
- Veröffentlicht 02.09.2026 15:40:47
- Zuletzt bearbeitet 22.09.2026 15:51:41
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.