Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown
CVE-2020-2279
Disclosure Date: September 23, 2020 (last updated October 25, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.
0
Attacker Value
Unknown
CVE-2020-2190
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2134
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.
0
Attacker Value
Unknown
CVE-2020-2135
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
0
Attacker Value
Unknown
CVE-2020-2110
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
0
Attacker Value
Unknown
CVE-2019-16538
Disclosure Date: November 21, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
0
Attacker Value
Unknown
CVE-2019-10431
Disclosure Date: October 01, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
0
Attacker Value
Unknown
CVE-2019-10400
Disclosure Date: September 12, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.
0
Attacker Value
Unknown
CVE-2019-10393
Disclosure Date: September 12, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.
0
Attacker Value
Unknown
CVE-2019-10394
Disclosure Date: September 12, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.
0