Impact
The Jenkins Script Security Plugin before version 1415.v9a_f9b_3a_c253d fails to verify calls that sandboxed scripts make to methods introduced at runtime. Because the plugin does not enforce the sandbox policy on these dynamic method calls, an attacker who can author and run sandboxed scripts—such as those defined in Jenkins Pipelines—can escape the sandbox and execute arbitrary code on the Jenkins master. This ability to bypass sandbox protection endangers the confidentiality, integrity, and availability of the entire Jenkins environment.
Affected Systems
The vulnerability affects all Jenkins instances that use the Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d or earlier. Any deployment that has the plugin installed at a vulnerable version is at risk. Jenkins versions using newer releases of the plugin are not affected.
Risk and Exploitability
The CVSS score of 7.5 classifies this flaw as a high‑impact vulnerability. The EPSS score of less than 1 % indicates a low public exploitation probability; it is not listed in the CISA KEV catalog. The exploitation path requires a user with permission to create and execute sandboxed scripts—typically a role such as 'Script' or 'Pipeline' author. Based on the description, it is inferred that an attacker could embed a call to a dynamically added method within a pipeline script, thereby bypassing sandbox checks and running code outside the restricted environment. Organizations that grant script or pipeline execution privileges broadly may therefore face a significant risk.
OpenCVE Enrichment