Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.plugins/script-security
  4. ›
  5. CVE-2017-1000107

CVE-2017-1000107: Incorrect Permission Assignment for Critical Resource

October 5, 2017 (updated October 3, 2019)

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.

References

  • jenkins.io/security/advisory/2017-08-07/
  • nvd.nist.gov/vuln/detail/CVE-2017-1000107

Code Behaviors & Features

Detect and mitigate CVE-2017-1000107 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 1.30

Fixed versions

  • 1.35

Solution

Upgrade to version 1.35 or above.

Impact 8.8 HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Source file

maven/org.jenkins-ci.plugins/script-security/CVE-2017-1000107.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:48 +0000.