Impact
The Jenkins Script Security Plugin fails to reject the @GroovyASTTransformationClass annotation in versions 1415.v9a_f9b_3a_c253d and earlier. An attacker who can run or modify sandboxed Jenkins Pipelines can inject this annotation, causing the Groovy compiler to execute a custom abstract syntax tree transformation during script compilation. This bypasses the intended sandbox restrictions and allows the attacker to run arbitrary code within the Jenkins controller JVM, effectively granting full control over the host machine.
Affected Systems
All Jenkins installations that have the Script Security Plugin version 1415.v9a_f9b_3a_c253d or earlier installed and where users have permission to create or edit pipelines. The plugin is part of the Jenkins Project, so any environment using that plugin is affected.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity and, although the EPSS score is less than 1% and it is not listed in CISA KEV, the potential impact is significant. The launch conditions require authenticated access to Jenkins with pipeline creation rights. Once an attacker submits a pipeline that contains the @GroovyASTTransformationClass annotation, the malicious AST transformation runs at compile time, leading to execution of arbitrary code within the Jenkins controller. The risk is mitigated by the low EPSS, but the severity warrants prompt action.
OpenCVE Enrichment