Impact
A flaw in the Jenkins Script Security Plugin prevents interception of operations that target a null receiver, including method calls, property accesses, and array indexing. This omission allows users who can define and run sandboxed scripts, such as Jenkins Pipelines, to bypass the sandbox mechanism and execute arbitrary code with the full privileges of the Jenkins controller JVM, thereby compromising confidentiality, integrity, and availability of the system.
Affected Systems
The Jenkins Script Security Plugin version 1415.v9a_f9b_3a_c253d or any earlier release is affected. The vulnerability applies to the Jenkins Project’s Script Security Plugin, which is used to sandbox Groovy scripts in Jenkins pipelines.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is an authorized Jenkins user who has the ability to create and execute sandboxed scripts; such a user can exploit the null receiver bypass to run malicious code on the controller. Successful exploitation would grant the attacker full control of the Jenkins instance.
OpenCVE Enrichment