-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from two key failures: 1) ScriptContent.createEngine didn't apply GroovySandbox when processing unapproved folder templates (fixed by introducing sandbox-aware SimpleTemplateEngine). 2) AbstractEvalContent.getManagedFile didn't properly distinguish between global/folder config files, allowing folder templates to avoid sandboxing. The patch added sandbox enforcement in both locations, confirming these were the vulnerable points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:email-ext | maven | <= 2.93 | 2.94 |
Ongoing coverage of React2Shell