PT-2026-84782 · Jenkins · Jenkins Script Security Plugin
CVE-2026-84659
·
Publicado
2026-09-02
·
Atualizado
2026-09-02
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Jenkins Script Security Plugin 1412.v7737b 3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins Script Security Plugin