Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvmf-36h5-3f5v

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Input Validation in Jenkins Script Security Plugin

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

Пакеты

Наименование

org.jenkins-ci.plugins:script-security

maven
Затронутые версииВерсия исправления

<= 1.69

1.70

EPSS

Процентиль: 79%
0.01291
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
redhat
почти 6 лет назад

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

CVSS3: 8.8
nvd
почти 6 лет назад

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

EPSS

Процентиль: 79%
0.01291
Низкий

8.8 High

CVSS3

Дефекты

CWE-20