Impact
The Jenkins Script Security Plugin (v1415.v9a_f9b_3a_c253d and earlier) incorrectly controls the operations performed by Groovy on collection elements that are cast to another type. This flaw allows a sandboxed script author to cast the collection itself to an arbitrary type, bypassing the sandbox and executing arbitrary code within the Jenkins controller JVM. The weakness results in a full remote code execution vulnerability for users who can create and run sandboxed scripts, including Pipeline authors.
Affected Systems
Jenkins Project – Jenkins Script Security Plugin, any version 1415.v9a_f9b_3a_c253d and earlier. All instances of Jenkins deployed with these plugin versions are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a lower likelihood of exploitation today. Nevertheless, the critical risk is that an attacker with permission to write or run sandboxed Groovy scripts can execute arbitrary code in the controller JVM, compromising the entire Jenkins environment. The likely attack vector is an insider or compromised account that can upload a malicious pipeline or script, or an attacker who gains such permissions remotely. The vulnerability hinges on unauthorized sandbox escapes, so any user with script execution rights is a potential vector.
OpenCVE Enrichment