Script Security
CloudBees CIVersion: 1361.v913100720139
Tier 1: Verified
Plugin ID: script-security
Minimum Jenkins required: 2.387.3
Last released: 1 day, 11 hours ago
Allows Jenkins administrators to control what in-process scripts can be run by less-privileged users.
Security Warnings
- Groovy sandbox protection incomplete(last version affected: 1.18)
- Unsafe methods in the default list of approved signatures(last version affected: 1.29)
- Multiple sandbox bypasses(last version affected: 1.30)
- Arbitrary file read vulnerability(last version affected: 1.36)
- Script Security sandbox bypass(last version affected: 1.47)
- Script Security sandbox bypass(last version affected: 1.49)
- Script Security sandbox bypass(last version affected: 1.50)
- Script Security sandbox bypass(last version affected: 1.52)
- Script security sandbox bypass(last version affected: 1.53)
- Script Security sandbox bypass(last version affected: 1.55)
- Sandbox bypass through type casts(last version affected: 1.61)
- Sandbox bypass through method pointer expressions(last version affected: 1.61)
- Sandbox bypass vulnerability(last version affected: 1.62)
- Sandbox bypass vulnerability(last version affected: 1.64)
- Sandbox bypass vulnerability(last version affected: 1.67)
- Sandbox bypass vulnerability(last version affected: 1.69)
- Sandbox bypass vulnerability(last version affected: 1.70)
- Stored XSS vulnerability(last version affected: 1.72)
- Sandbox bypass vulnerability(last version affected: 1.74)
- CSRF vulnerability(last version affected: 1158.v7c1b_73a_69a_08)
- Sandbox bypass vulnerability(last version affected: 1183.v774b_0b_0a_a_451)
- Whole-script approval vulnerable to SHA-1 collisions(last version affected: 1189.vb_a_b_7c8fd5fde)
- Sandbox bypass vulnerability(last version affected: 1228.vd93135a_2fb_25)
- Multiple sandbox bypass vulnerabilities(last version affected: 1335.vf07d9ce377a_e)
Download PluginOlder versions
Script Security 1361.v913100720139
SHA1:
b6fb3fcae47e8037f1db8868e07ec6b8dc59f068
SHA256:
0dbd3f551e39ac823ac88ae5f946ee53c861b74028345ad5323222f637f0e2ce
Maintainers:
- Jesse Glick
- Kohsuke Kawaguchi
- Andrew Bayer
- Sam Van Oort
- rsandell
- Devin Nusbaum
- Carroll Chiou
- Liam Newman
- Karl Shultz
Dependencies: