Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9533 | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. |
Github GHSA |
GHSA-4vjp-327p-w4qv | Jenkins Templating Engine Plugin Vulnerable to Arbitrary Code Execution |
Tue, 29 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins templating Engine |
|
| CPEs | cpe:2.3:a:jenkins:templating_engine:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins templating Engine |
Wed, 02 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-02-26T18:29:00.764Z
Reserved: 2025-04-01T12:50:10.765Z
Link: CVE-2025-31722
Updated: 2025-04-02T16:53:02.053Z
Status : Analyzed
Published: 2025-04-02T15:15:59.680
Modified: 2025-04-29T13:52:56.227
Link: CVE-2025-31722
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA