Versions
1.67 and earlier
1.64 and earlier
1183.v774b_0b_0a_a_451
1.50 and earlier
1.69
1.62 and earlier
1189.vb_a_b_7c8fd5fde
1175.1177.vda_175b_77d144
1158.v7c1b_73a_69a_08
1.70
1.55 and earlier
1.53 and earlier
1.66.5
1175.1179.vea_f7532629e1
1.61 and earlier
1145.1148.vf6d17a_a_a_eef6
1.74
1.72
1.52 and earlier
1.78.1
1335.vf07d9ce377a_e
0
1175.1180.v36a_3fb_2dec9c
unspecified
1228.vd93135a_2fb_25
1366.vd44b_49a_5c85c
1367.vdf2fc45f229c
1365.v4778ca_84b_de5
1362.v67dc1f0e1b_b_3
Recent CVEs
CVE-2024-52549
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
CVE-2024-34145
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CVE-2024-34144
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CVE-2020-2134
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.