A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HJenkins Script Security
APPJenkins≤ 1.55Red Hat OpenShift Container Platform
APPRedhat3.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
References
Related vulnerabilities
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
CVE-2026-4408CRITICAL9.0PL ✓same product
Samba: RCE przez command injection w 'check password script' z podstawieniem %u