io.jenkins.plugins:pipeline-groovy-lib
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.jenkins.plugins:pipeline-groovy-libpage 1 of 1
- CVE-2022-43405CRITICALCVSS 9.9EG 9.9fixed in 613.v9c41a_160233f2022-10-19
vulnerable: 589.vb_a_b_4a_a_8c443c ... 612.v84da_9c54906d (7 versions)
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines…
- CVE-2022-43406CRITICALCVSS 9.9EG 9.9fixed in 613.v9c41a_160233f2022-10-19
vulnerable: 589.vb_a_b_4a_a_8c443c ... 612.v84da_9c54906d (7 versions)
A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, includin…
- CVE-2026-48921HIGHCVSS 7.5EG 7.5fixed in 798.v5cc6888253122026-05-27
vulnerable: 589.vb_a_b_4a_a_8c443c ... 797.v90ea_a_9b_e45a_0 (32 versions)
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on…
- CVE-2026-57283MEDIUMCVSS 4.3EG 4.3fixed in 4331.43332026-06-24
vulnerable: 589.vb_a_b_4a_a_8c443c ... 806.v408277b_33d1d (35 versions)
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline…
- CVE-2026-57284MEDIUMCVSS 4.3EG 4.3fixed in 4331.43332026-06-24
vulnerable: 589.vb_a_b_4a_a_8c443c ... 806.v408277b_33d1d (35 versions)
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration othe…
Check whether io.jenkins.plugins:pipeline-groovy-lib is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.jenkins.plugins:pipeline-groovy-lib CVEs against the assets you own.
Book a Demo →