Database/Control plane, storage & DevOps
Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator to
Impact
Script Security normally requires an administrator to approve a Groovy classpath entry before it can be used. In versions 1415.v9af9b3ac253d and earlier the approval is granted automatically when a user with Overall/Administer copies an item, or when the configuration is updated through the REST API or the CLI. An attacker who can define classpath entries in a job configuration therefore gets arbitrary code execution inside the Jenkins controller JVM. On a build fleet that drives GPU cluster deployments, the controller usually holds registry credentials, kubeconfigs and signing keys, so controller RCE converts directly into the ability to push images and manifests that land on GPU nodes.
Who can reach it
A user who can define classpath entries in an item configuration, combined with an Overall/Administer user copying that item or submitting the configuration via REST API or CLI. Authenticated access to the Jenkins controller is required; the admin action supplies the trigger.
What to do
Update the Script Security Plugin past 1415.v9af9b3ac253d via the Jenkins update center and restart the controller; plugin updates on the controller mean a short controller outage while builds are queued, no agent or GPU node action. Until then, review the pending and approved script-approval list for classpath entries that were never approved by a human, and avoid copying items or pushing job configs through the API/CLI. The advisory does not name a configuration-only mitigation.
References
Related entries
- Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UICVE-2026-92134 · Jenkins Warnings Plugin (analysis results ID validation)High
- Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UICVE-2026-92135 · Jenkins Coverage Plugin (coverage results ID validation)High
- Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSSCVE-2026-92136 · Jenkins OWASP Dependency-Check Plugin (report CWE rendering)High
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.