VendorsJenkinsscript_securityall versions
Vulnerabilities

Jenkins Script Security

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2022-30946
A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.
Published 2022-05-17 · Modified
4.3EPSS 0.006
CVE-2024-52549
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Published 2024-11-13 · Analyzed
4.3EPSS 0.004
CVE-2026-84658
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.
Published 2026-09-02 · Analyzed
4.3EPSS 0.003
CVE-2026-84659
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
Published 2026-09-02 · Analyzed
4.3EPSS 0.003
CVE-2026-42519
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
Published 2026-04-29 · Analyzed
4.3EPSS 0.003
← Prev2 / 2