ZeroHour

CVE-2017-2650

CVSS 3.0
8.5 high
EPSS
1%p65
Published
()
Modified
Description

It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.

Vendors
jenkins
Products
pipeline classpath step
Weakness
CWE-592
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.