-
CVSS Score
-The vulnerability stemmed from Jenkins' failure to restrict AST transformations during script compilation in sandboxed environments. Key evidence includes:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins.workflow:workflow-cps-parent | maven | <= 2.61 | 2.61.1 |
| org.jenkins-ci.plugins:pipeline-model-definition | maven | <= 1.3.4 | 1.3.4.1 |
| org.jenkins-ci.plugins:script-security | maven | <= 1.49 | 1.50 |