CVE-2016-3102
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
09/02/2017
Last modified:
20/04/2025
Description
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:script_security:1.0:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.1:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.2:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.3:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.4:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.5:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.6:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.7:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.8:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.9:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.10:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.11:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.12:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.13:*:*:*:*:jenkins:*:* | ||
| cpe:2.3:a:jenkins:script_security:1.14:*:*:*:*:jenkins:*:* |
To consult the complete list of CPE names with products and versions, see this page



