Database/Control plane, storage & DevOps
Jenkins Script Security Plugin: form submission exposes the script approval configuration to attackers
Impact
A @DataBoundConstructor on a constructor that loads script approval configuration lets a user able to submit certain forms read that configuration. The approval list reveals which scripts and signatures the controller already trusts, which is direct reconnaissance for anyone probing the sandbox boundary on a build system. Disclosure only - no execution and no write - but it lowers the cost of a follow-on sandbox bypass on the controller that builds artifacts for the fleet. Affects Script Security Plugin 1412.v7737b_3405f86 and earlier.
Who can reach it
Authenticated low-privileged Jenkins user able to submit the affected forms over the network. No administrator rights required.
What to do
Update the Script Security Plugin past 1412.v7737b_3405f86 per the 2026-09-02 advisory (SECURITY-3986). Plugin update and controller restart; no node drain. Low urgency on its own, but bundle it with the other Script Security fix in the same advisory.
References
Related entries
- Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcementCVE-2026-84659 · Jenkins Script Security Plugin (global sandbox enforcement setting)Medium
- Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URLCVE-2026-84662 · Jenkins LDAP plugin (Stapler data binding, attacker-specified connection URL)Medium
- Jenkins Parameterized Remote Trigger plugin: remote trigger tokens stored unencrypted in job config.xmlCVE-2026-84676 · Jenkins Parameterized Remote Trigger plugin (tokens stored unencrypted in job config.xml)Medium
- GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rightsCVE-2026-8667 · GitLab CE/EE (package registry metadata authorization)Medium
- Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSACVE-2024-45678 · Infineon cryptographic library (ECDSA) in security microcontrollersMedium
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.