Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2w2h-gwwj-fh3q

Опубликовано: 24 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

EPSS

Процентиль: 20%
0.00275
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

EPSS

Процентиль: 20%
0.00275
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-470