GHSA-qjq3-wqj5-g37q

Suggest an improvement
Source
https://github.com/advisories/GHSA-qjq3-wqj5-g37q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qjq3-wqj5-g37q/GHSA-qjq3-wqj5-g37q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qjq3-wqj5-g37q
Aliases
Published
2026-05-27T15:33:26Z
Modified
2026-07-01T19:41:29Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
Details

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries.

This allows attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

Pipeline: Groovy Libraries Plugin 798.v5cc688825312 prohibits symbolic links in shared libraries.

Database specific
{
    "cwe_ids":  [
        "CWE-59"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-01T19:26:57Z",
    "nvd_published_at":  "2026-05-27T15:16:31Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / io.jenkins.plugins:pipeline-groovy-lib

Package

Name
io.jenkins.plugins:pipeline-groovy-lib
View open source insights on deps.dev
Purl
pkg:maven/io.jenkins.plugins/pipeline-groovy-lib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
798.v5cc688825312

Affected versions

589.*
589.vb_a_b_4a_a_8c443c
591.*
591.v3a_7f422b_d058
593.*
593.va_a_fc25d520e9
593.595.vfc6485d13dcd
598.*
598.vcd66b_a_336510
612.*
612.v84da_9c54906d
612.614.v48dcb_f62a_640
613.*
613.v9c41a_160233f
621.*
621.vb_44ce045b_582
629.*
629.vb_5627b_ee2104
656.*
656.va_a_ceeb_6ffb_f7
671.*
671.v07c339c842e8
673.*
673.vb_c5d5948283c
685.*
685.v8ee9ed91d574
687.*
687.v62591d623759
689.*
689.veec561a_dee13
700.*
700.v0e341fa_57d53
704.*
704.vc58b_8890a_384
710.*
710.v4b_94b_077a_808
727.*
727.ve832a_9244dfa_
730.*
730.ve57b_34648c63
740.*
740.va_2701257fe8d
744.*
744.v5b_556ee7c253
745.*
745.vdf6077913de0
749.*
749.v70084559234a_
751.*
751.v709f84f7d768
752.*
752.vdddedf804e72
763.*
763.v13008816b_de7
766.*
766.v2b_e08c2e6ff2
776.*
776.vfee5327b_b_a_5b_
787.*
787.ve2fef0efdca_6
797.*
797.v90ea_a_9b_e45a_0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qjq3-wqj5-g37q/GHSA-qjq3-wqj5-g37q.json"