Impact
The Jenkins Script Security Plugin, through version 1415.v9a_f9b_3a_c253d, fails to reject @Builder annotations whose builderStrategy member names an arbitrary class. This flaw allows an attacker with permission to write and run sandboxed scripts—such as Pipelines—to instruct the plugin to instantiate and execute that class, thereby running code outside the enforced sandbox. Because the plugin uses the class name supplied in the annotation, any suitable class present on the classpath of the component that evaluates the script can be leveraged, leading to full code execution inside the Jenkins process. This vulnerability falls under improper restriction of code execution (CWE‑470).
Affected Systems
Jenkins installations that use the Script Security Plugin version 1415.v9a_f9b_3a_c253d or earlier are affected. Affected systems require that a component capable of evaluating sandboxed scripts has the attacker’s class available on its classpath. Attackers need script‑execution rights within the Jenkins environment, typically granted to trusted users creating or managing Pipelines.
Risk and Exploitability
The flaw carries a high CVSS score of 7.2, yet its EPSS score is less than 1 % and it is not listed in the CISA KEV catalog. The likely attack vector, based on the description, is a local attacker who already possesses the privilege to author or execute sandboxed scripts; upon doing so, the attacker can trigger the plugin to load the arbitrary class. Because the vulnerability leads to arbitrary code execution with the same privileges as the Jenkins process, it poses a severe confidentiality, integrity, and availability risk. Consequently, the vulnerability should be treated as high priority and patched promptly.
OpenCVE Enrichment