The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2025-03-13T19:05:08Z",
"nvd_published_at": "2017-02-09T15:59:00Z",
"severity": "HIGH"
}