Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57284

Опубликовано: 24 июн. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:pipeline\:_groovy:*:*:*:*:*:jenkins:*:*
Версия до 4331.v9d06ed4658ff (включая)

EPSS

Процентиль: 27%
0.00338
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 4.3
github
2 месяца назад

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

EPSS

Процентиль: 27%
0.00338
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-470