Description
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4100 | Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection. |
Github GHSA |
GHSA-h7rx-r733-7x7r | Sandbox bypass in Jenkins Script Security Plugin sandbox bypass |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:50:42.555Z
Reserved: 2017-10-03T00:00:00.000Z
Link: CVE-2017-1000107
No data.
Status : Deferred
Published: 2017-10-05T01:29:04.307
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000107
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA