AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-1000505

MEDIUM · CVSS 6.5 EPSS 0.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-01-25 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Jenkins.

CVE
CVE-2017-1000505
Severity
MEDIUM
CVSS
6.5
EPSS
0.99%
Jenkins

Original NVD Description

In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.

Related CVEs

Other vulnerabilities affecting the same vendor(s)