CVE-2025-31722 – Jenkins Templating Engine Plugin Sandbox Bypass

The following table lists the changes that have been made to the
CVE-2025-31722 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 02, 2025

    Action Type Old Value New Value
    Added Description In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
    Added Reference https://www.jenkins.io/security/advisory/2025-04-02/#SECURITY-3505
Share the Post:

Related Posts