Database/Control plane, storage & DevOps
Jenkins Script Security Plugin: @Builder builderStrategy escapes the Groovy sandbox
Impact
The plugin does not reject @Builder annotations whose builderStrategy member names an arbitrary class, so anyone allowed to define and run a sandboxed script - including an ordinary Pipeline - can execute code outside the sandbox, provided a suitable class sits on the classpath of the script-evaluating component. That is code execution as the Jenkins controller process, and CVSS marks a scope change (S:C). For a GPU fleet the Jenkins controller is usually the thing holding registry credentials, kubeconfigs and node SSH keys for the build and model-release pipelines, so a sandbox escape by a developer with only Pipeline-authoring rights turns into control over what images and model artifacts land on the GPU nodes. The sandbox is the entire authorization boundary here: exploitation needs no admin rights, only permission to run a job.
Who can reach it
Any authenticated Jenkins user with permission to define and run sandboxed scripts or Pipelines, reachable over the network wherever the controller UI or SCM-driven pipelines are. Authentication required, but only at low privilege (PR:L); AC:H because a usable class must be on the classpath.
What to do
Upgrade Script Security Plugin past 1415.v9a_f9b_3a_c253d per the Jenkins advisory of 2026-09-16 and restart the controller - a plugin update plus controller restart, which interrupts running builds but touches no GPU nodes. The record does not name the fixed release; take it from the advisory. Until then, restrict who may define and run Pipeline scripts and require admin approval for script changes.
References
Related entries
- Ceph RGW (STS session tokens): Any tenant holding one ordinary STS session token can edit it into RGW superuser. RGWNCVD-2026-040-ceph-rgw-sts-session-tokens · Ceph RGW (STS session tokens)High
- CloudNativePG (role password handling, pg_stat_statements exposure): CREDENTIAL DISCLOSURE ACROSS THE TENANT BOUNDARYNCVD-2026-049-cloudnativepg-role-password-hand · CloudNativePG (role password handling, pg_stat_statements exposure)High
- IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleCVE-2022-41736 · IBM Spectrum Scale Container Native Storage AccessHigh
- ConnectWise ScreenConnect: Path traversal enabling remote code executionCVE-2024-1708 · ConnectWise ScreenConnectHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMDCVE-2024-36352 · AMD Graphics Driver - crafted pointer leading to arbitrary writesHigh
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemCVE-2025-30479 · Dell CloudLink (command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.