Back to CVE List

CVE-2026-57280

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-693
Source
NVD
Vendor
Jenkins Project
Product
Jenkins Script Security Plugin

External References

Discussion (0)

Add Comment

No comments yet. Be the first!