Impact
The Jenkins Script Security Plugin allows a user with overall administration rights to copy items or update them through the REST API or CLI, and in doing so it automatically approves any classpath entries defined in the configuration. Because the plugin does not perform input validation on these classpath values, an attacker can inject malicious classpaths that are loaded by the Jenkins controller JVM, leading to arbitrary code execution. This weakness corresponds to code injection (CWE‑94).
Affected Systems
The vulnerability is present in Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and earlier, as identified by the Jenkins Project. All installations running those plugin versions are affected; newer releases contain the fix. The plugin is part of the Jenkins core ecosystem and is widely deployed in CI/CD pipelines.
Risk and Exploitability
The CVSS score of 8 indicates high severity, while the EPSS score of less than 1% shows low current exploitation probability but the vulnerability is not yet in the CISA KEV list. Attackers would need to act as an administrator to leverage the REST API, CLI, or GUI to copy or edit items. Given the high potential impact of arbitrary code execution in the controller JVM, the risk remains significant, especially for environments with broad admin permissions.
OpenCVE Enrichment