7.5
CVSSv2

CVE-2016-3102

Published: 09/02/2017 Updated: 28/02/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Script Security plugin prior to 1.18.1 in Jenkins might allow remote malicious users to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins script security 1.10

jenkins script security 1.9

jenkins script security 1.8

jenkins script security 1.7

jenkins script security 1.13

jenkins script security 1.11

jenkins script security 1.6

jenkins script security 1.4

jenkins script security 1.18

jenkins script security 1.17

jenkins script security 1.16

jenkins script security 1.15

jenkins script security 1.2

jenkins script security 1.1

jenkins script security 1.0

jenkins script security 1.14

jenkins script security 1.12

jenkins script security 1.5

jenkins script security 1.3

Vendor Advisories

The Script Security plugin before 1181 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations ...