Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57280

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 8.8

Описание

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

A flaw was found in Jenkins Script Security Plugin. This vulnerability allows attackers who can provide sandboxed Groovy scripts to bypass security sandbox protections. By exploiting a failure to properly intercept implicit type casts in typed for-each loops, an attacker can invoke arbitrary constructors, potentially leading to arbitrary code execution within the Jenkins environment.

Отчет

Red Hat rates this as an Important vulnerability in the Jenkins Script Security Plugin. Attackers with the ability to provide sandboxed Groovy scripts can bypass sandbox protections due to improper handling of implicit type casts in typed for-each loops, allowing arbitrary constructor invocation and potential code execution within the Jenkins JVM. The scope is unchanged (S:U) because the sandbox and the Jenkins controller share the same security authority — a sandbox escape executes code in the same context rather than crossing a trust boundary to a separate system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel9Not affected
OpenShift Developer Tools and Services 4.12ocp-tools-4/jenkins-rhel8FixedRHSA-2026:6024726.08.2026
OpenShift Developer Tools and Services 4.13ocp-tools-4/jenkins-rhel8FixedRHSA-2026:6024926.08.2026
OpenShift Developer Tools and Services 4.14ocp-tools-4/jenkins-rhel8FixedRHSA-2026:6024826.08.2026
OpenShift Developer Tools and Services 4.15ocp-tools-4/jenkins-rhel8FixedRHSA-2026:6023926.08.2026
OpenShift Developer Tools and Services 4.16ocp-tools-4/jenkins-rhel9FixedRHSA-2026:6025126.08.2026
OpenShift Developer Tools and Services 4.17ocp-tools-4/jenkins-rhel9FixedRHSA-2026:6024626.08.2026
OpenShift Developer Tools and Services 4.18ocp-tools-4/jenkins-rhel9FixedRHSA-2026:6025026.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1287
https://bugzilla.redhat.com/show_bug.cgi?id=2492199jenkins-script-security-plugin: Jenkins Script Security Plugin: Sandbox bypass leading to arbitrary code execution

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

CVSS3: 8.8
github
3 месяца назад

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

8.8 High

CVSS3