PT-2026-51790 · Jenkins · Script Security Plugin
CVE-2026-57280
·
Published
2026-06-24
·
Updated
2026-06-26
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Script Security Plugin versions prior to 1402.v94c9ce464861
Description
Sandboxed Groovy scripts fail to intercept implicit type casts applied to elements of typed for-each loops. This allows attackers who can provide such scripts to invoke arbitrary constructors and bypass sandbox protection.
Recommendations
Update Jenkins Script Security Plugin to a version later than 1402.v94c9ce464861.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Script Security Plugin