Jenkins Templating Engine Plugin
cpe:2.3:a:jenkins:templating_engine:*:*:*:*:jenkins:*:*
- <= 2.5.3
A script security sandbox bypass vulnerability has been identified in the Jenkins Templating Engine Plugin versions through 2.5.3. Libraries defined in folders are not subject to sandbox protection, allowing users with Item/Configure permission to execute arbitrary code in the Jenkins controller JVM.
Exploitation of this vulnerability allows for arbitrary code execution in the context of the Jenkins controller JVM.
Users of the Templating Engine Plugin should update to version 2.5.4, which applies the necessary sandbox protection to libraries defined in folders.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.