Vulnerability GHSA-p334-gfhq-c7w6

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
April 29, 2026 at 03:30 PM UTC
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1

Summary

Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths

Details

Jenkins Script Security Plugin versions 1399.ve6a_66547f6e1 and earlier do not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.

Script Security Plugin 1402.v94c9ce464861 requires Overall/Administer permission to enumerate pending and approved Script Security classpaths.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 months ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
High Risk
3 months ago
Jenkins Script Security Plugin has a script security bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-cfj9-2vgr-hpxp
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-cfj9-2vgr-hpxp
Medium Risk
1 year ago
Missing permission check in Jenkins Script Security Plugin
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-jv82-75fh-23r7
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-jv82-75fh-23r7
High Risk
2 years ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
High Risk
2 years ago
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
View all vulnerabilities for these packages

Timeline

Published
5 months ago
April 29, 2026 at 03:30 PM UTC
Last Modified
18 days ago
September 10, 2026 at 03:51 AM UTC