Database/Control plane, storage & DevOps
Jenkins Script Security Plugin: approved JAR is re-downloaded, letting a second payload load into the controller
Impact
The plugin fetches a classpath JAR from a URL twice: it approves the first copy and then loads the second. Anyone who can define a classpath entry can have a benign JAR approved and a different one executed, giving arbitrary code execution inside the Jenkins controller JVM. On a fleet whose CI controller holds registry push credentials, kubeconfigs and cluster tokens, controller RCE is the shortest path from a build job to the GPU cluster's control plane. Affects Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier.
Who can reach it
An authenticated Jenkins user with permission to define classpath entries for scripts or Pipelines, plus the ability to host the JAR URL the controller fetches.
What to do
Update the Script Security Plugin past 1415.v9a_f9b_3a_c253d per the Jenkins advisory and restart the controller; plugin upgrades on Jenkins are a controller restart, not a fleet-wide action. Until then, review who holds script-approval and classpath-definition rights. No agent or GPU node reboot is involved.
References
Related entries
- Jenkins Script Security Plugin: sandbox does not check dynamically added methods, allowing escapeCVE-2026-92129 · Jenkins Script Security Plugin (Groovy sandbox, runtime-added methods)High
- ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worseCVE-2020-13817 · ntpd (transmit timestamp prediction)High
- Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk itsCVE-2021-1228 · Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN)High
- HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear whenCVE-2021-45104 · HTCondor (daemon-to-daemon channel, negotiator/startd/schedd)High
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationCVE-2022-31671 · Harbor registryHigh
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedCVE-2022-35919 · MinIO (admin server-update API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.