Impact
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier contains a flaw that downloads a JAR file from a specified URL twice—first to confirm approval and second to load classpath entries. An attacker who can define classpath entries can manipulate the second download to inject arbitrary code, which is then executed within the Jenkins controller JVM, giving full control over the server.
Affected Systems
The vulnerability affects Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and all earlier releases of the plugin. Any Jenkins instance that relies on these older plugin versions is potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability and the EPSS score of less than 1% shows that exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation would most likely occur via a remote attacker able to invoke the plugin’s functionality, allowing them to set classpath entries and trigger code execution on the Jenkins controller.
OpenCVE Enrichment