GHSA-72gx-qq2m-6xr2
GitHub Security Advisory
Improper Control of Generation of Code in Jenkins Script Security Plugin
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
Affected Packages
Maven
org.jenkins-ci.plugins:script-security
Affected versions:
0
(fixed in 1.65)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 7, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.