PT-2026-51794 · Jenkins · Pipeline: Groovy Plugin
CVE-2026-57284
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Pipeline: Groovy Plugin versions prior to 4331.v9d06ed4658ff
Description
Insufficient restriction on the types that can be instantiated through the Pipeline Snippet Generator allows attackers to instantiate types related to system or job configuration instead of only Pipeline steps.
Recommendations
Update Jenkins Pipeline: Groovy Plugin to a version later than 4331.v9d06ed4658ff.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pipeline: Groovy Plugin