Security Advisory

CVE-2025-31722

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-04-02 14:59:50
Last updated 2026-02-26 18:29:00
Assigner jenkins
CVSS score 8.8
State PUBLISHED

Description

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.