CVE-2017-1000107 Information
Feb 14, 2021
cve
Description
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list super constructor invocations method references and type coercion expressions. This could be used to invoke arbitrary constructors and methods bypassing sandbox protection.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://jenkins.io/security/advisory/2017-08-07/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: