Vulnerability Description
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Script Security | 1.0 |
Related Weaknesses (CWE)
References
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-04-1Vendor Advisory
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-04-1Vendor Advisory
FAQ
What is CVE-2016-3102?
CVE-2016-3102 is a vulnerability with a CVSS score of 7.3 (HIGH). The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array...
How severe is CVE-2016-3102?
CVE-2016-3102 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-3102?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Script Security.