Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
References
Configurations
History
30 Jun 2026, 03:21
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-917 |
27 Jun 2026, 19:27
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3793 - Vendor Advisory | |
| First Time |
Jenkins
Jenkins script Security |
|
| CPE | cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:* |
24 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-693 CWE-93 |
24 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 14:17
Updated : 2026-07-15 01:16
NVD link : CVE-2026-57281
Mitre link : CVE-2026-57281
CVE.ORG link : CVE-2026-57281
JSON object : View
Products Affected
jenkins
- script_security
