GHSA-mj9c-vjp9-pggh
GitHub Security Advisory
Incorrect Authorization in Puppet Enterprise Pipeline Jenkins Plugin
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
Affected Packages
Maven
org.jenkins-ci.plugins.workflow:puppet-enterprise-pipeline
Affected versions:
0
(last affected: 1.3.1)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.