-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:ontrack | maven | < 3.4.1 | 3.4.1 |
The vulnerability stemmed from improper sandbox application during Groovy script lifecycle phases. The patch changes show:
The original AbstractDSLLauncher's script parsing before binding setup, and SandboxDSLLauncher's post-parsing sandbox application, allowed attackers to bypass restrictions during critical initialization phases of script execution.
Ongoing coverage of React2Shell