[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2018-1000865":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":264,"aliases":265,"duplicate_of":9,"upstream":267,"downstream":268,"duplicates":271,"related":272,"reserved_at":9,"published_at":273,"modified_at":274,"state":275,"summary":276,"references_raw":285,"kevs":314,"epss":315,"epss_history":318,"metrics":574,"affected":587},"CVE-2018-1000865","A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-269","Improper Privilege Management","The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.","weakness","Draft","Class","Medium",[20,182,260],{"id":21,"name":22,"techniques":23},"CAPEC-122","Privilege Abuse",[24],{"id":25,"name":26,"tactics":27,"countermeasures":34},"T1548","Abuse Elevation Control Mechanism",[28,31],{"id":29,"name":30},"TA0030","Defense Evasion",{"id":32,"name":33},"TA0111","Privilege Escalation",[35,40,44,48,52,57,61,65,69,73,77,81,85,89,94,98,103,108,112,116,120,125,129,133,137,141,146,150,154,158,162,166,170,174,178],{"id":36,"name":37,"tactic":38},"D3-CI","Configuration Inventory",{"name":39},"Model",{"id":41,"name":42,"tactic":43},"D3-AM","Access Modeling",{"name":39},{"id":45,"name":46,"tactic":47},"D3-DI","Data Inventory",{"name":39},{"id":49,"name":50,"tactic":51},"D3-NTPM","Network Traffic Policy Mapping",{"name":39},{"id":53,"name":54,"tactic":55},"D3-AEM","Application Exception Monitoring",{"name":56},"Detect",{"id":58,"name":59,"tactic":60},"D3-SCA","System Call Analysis",{"name":56},{"id":62,"name":63,"tactic":64},"D3-SFA","System File Analysis",{"name":56},{"id":66,"name":67,"tactic":68},"D3-FA","File Analysis",{"name":56},{"id":70,"name":71,"tactic":72},"D3-FIM","File Integrity Monitoring",{"name":56},{"id":74,"name":75,"tactic":76},"D3-OPM","Operational Process Monitoring",{"name":56},{"id":78,"name":79,"tactic":80},"D3-DA","Dynamic Analysis",{"name":56},{"id":82,"name":83,"tactic":84},"D3-EFA","Emulated File Analysis",{"name":56},{"id":86,"name":87,"tactic":88},"D3-PSA","Process Spawn Analysis",{"name":56},{"id":90,"name":91,"tactic":92},"D3-FEV","File Eviction",{"name":93},"Evict",{"id":95,"name":96,"tactic":97},"D3-AL","Account Locking",{"name":93},{"id":99,"name":100,"tactic":101},"D3-DF","Decoy File",{"name":102},"Deceive",{"id":104,"name":105,"tactic":106},"D3-FE","File Encryption",{"name":107},"Harden",{"id":109,"name":110,"tactic":111},"D3-AA","Agent Authentication",{"name":107},{"id":113,"name":114,"tactic":115},"D3-CDP","Change Default Password",{"name":107},{"id":117,"name":118,"tactic":119},"D3-SCP","System Configuration Permissions",{"name":107},{"id":121,"name":122,"tactic":123},"D3-RC","Restore Configuration",{"name":124},"Restore",{"id":126,"name":127,"tactic":128},"D3-RF","Restore File",{"name":124},{"id":130,"name":131,"tactic":132},"D3-ULA","Unlock Account",{"name":124},{"id":134,"name":135,"tactic":136},"D3-RUAA","Restore User Account Access",{"name":124},{"id":138,"name":139,"tactic":140},"D3-RD","Restore Database",{"name":124},{"id":142,"name":143,"tactic":144},"D3-SCF","System Call Filtering",{"name":145},"Isolate",{"id":147,"name":148,"tactic":149},"D3-CF","Content Filtering",{"name":145},{"id":151,"name":152,"tactic":153},"D3-LFP","Local File Permissions",{"name":145},{"id":155,"name":156,"tactic":157},"D3-RFAM","Remote File Access Mediation",{"name":145},{"id":159,"name":160,"tactic":161},"D3-CQ","Content Quarantine",{"name":145},{"id":163,"name":164,"tactic":165},"D3-CM","Content Modification",{"name":145},{"id":167,"name":168,"tactic":169},"D3-UAP","User Account Permissions",{"name":145},{"id":171,"name":172,"tactic":173},"D3-EAL","Executable Allowlisting",{"name":145},{"id":175,"name":176,"tactic":177},"D3-EDL","Executable Denylisting",{"name":145},{"id":179,"name":180,"tactic":181},"D3-HBPI","Hardware-based Process Isolation",{"name":145},{"id":183,"name":33,"techniques":184},"CAPEC-233",[185],{"id":25,"name":26,"tactics":186,"countermeasures":189},[187,188],{"id":29,"name":30},{"id":32,"name":33},[190,192,194,196,198,200,202,204,206,208,210,212,214,216,218,220,222,224,226,228,230,232,234,236,238,240,242,244,246,248,250,252,254,256,258],{"id":36,"name":37,"tactic":191},{"name":39},{"id":41,"name":42,"tactic":193},{"name":39},{"id":45,"name":46,"tactic":195},{"name":39},{"id":49,"name":50,"tactic":197},{"name":39},{"id":53,"name":54,"tactic":199},{"name":56},{"id":58,"name":59,"tactic":201},{"name":56},{"id":62,"name":63,"tactic":203},{"name":56},{"id":66,"name":67,"tactic":205},{"name":56},{"id":70,"name":71,"tactic":207},{"name":56},{"id":74,"name":75,"tactic":209},{"name":56},{"id":78,"name":79,"tactic":211},{"name":56},{"id":82,"name":83,"tactic":213},{"name":56},{"id":86,"name":87,"tactic":215},{"name":56},{"id":90,"name":91,"tactic":217},{"name":93},{"id":95,"name":96,"tactic":219},{"name":93},{"id":99,"name":100,"tactic":221},{"name":102},{"id":104,"name":105,"tactic":223},{"name":107},{"id":109,"name":110,"tactic":225},{"name":107},{"id":113,"name":114,"tactic":227},{"name":107},{"id":117,"name":118,"tactic":229},{"name":107},{"id":121,"name":122,"tactic":231},{"name":124},{"id":126,"name":127,"tactic":233},{"name":124},{"id":130,"name":131,"tactic":235},{"name":124},{"id":134,"name":135,"tactic":237},{"name":124},{"id":138,"name":139,"tactic":239},{"name":124},{"id":142,"name":143,"tactic":241},{"name":145},{"id":147,"name":148,"tactic":243},{"name":145},{"id":151,"name":152,"tactic":245},{"name":145},{"id":155,"name":156,"tactic":247},{"name":145},{"id":159,"name":160,"tactic":249},{"name":145},{"id":163,"name":164,"tactic":251},{"name":145},{"id":167,"name":168,"tactic":253},{"name":145},{"id":171,"name":172,"tactic":255},{"name":145},{"id":175,"name":176,"tactic":257},{"name":145},{"id":179,"name":180,"tactic":259},{"name":145},{"id":261,"name":262,"techniques":263},"CAPEC-58","Restful Privilege Elevation",[],[],[266],"GHSA-p4p5-3v2j-w5rv",[],[269],{"_key":270},"RHBA-2019:0326",[],[],"2018-12-10T14:00:00.000Z","2024-08-05T12:47:57.160Z","Modified",{"cisa_kev":277,"cisa_ransomware":277,"cisa_vendor":9,"epss_severity":278,"epss_score":279,"severity":280,"severity_score":281,"severity_version":282,"severity_source":283,"severity_vector":284,"severity_status":275},false,"low",0.00615,"high",8.8,"v3.0","nvd","CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[286,295,301,305,310],{"url":287,"sources":288,"tags":291},"https://jenkins.io/security/advisory/2018-10-29/#SECURITY-1186",[289,283,290],"cve.org","osv_maven",[292,293,294],"X Refsource CONFIRM","Vendor Advisory","WEB",{"url":296,"sources":297,"tags":298},"https://access.redhat.com/errata/RHBA-2019:0326",[289,283,290],[293,299,300,294],"X Refsource REDHAT","Third Party Advisory",{"url":302,"sources":303,"tags":304},"https://access.redhat.com/errata/RHBA-2019:0327",[289,283,290],[293,299,300,294],{"url":306,"sources":307,"tags":308},"https://nvd.nist.gov/vuln/detail/CVE-2018-1000865",[290],[309],"Advisory",{"url":311,"sources":312,"tags":313},"https://github.com/jenkinsci/script-security-plugin/commit/16c862ae9d4038a3edbd8bdfb0fd1401a509d56b",[290],[294],[],{"date":316,"score":279,"percentile":317},"2026-06-04",0.70277,[319,323,326,329,332,334,336,339,342,345,348,351,354,357,359,362,365,368,371,374,377,380,383,386,389,392,395,398,401,404,407,410,413,415,417,419,422,425,428,431,433,436,439,442,445,448,451,454,456,459,462,465,468,470,473,475,477,479,482,485,488,491,494,497,499,502,505,508,510,513,516,519,522,525,528,531,534,537,540,543,546,549,552,555,557,559,562,565,568,571],{"date":320,"score":321,"percentile":322},"2025-11-04",0.00639,0.6971,{"date":324,"score":321,"percentile":325},"2025-11-05",0.69695,{"date":327,"score":321,"percentile":328},"2025-11-06",0.69693,{"date":330,"score":321,"percentile":331},"2025-11-07",0.69705,{"date":333,"score":321,"percentile":331},"2025-11-08",{"date":335,"score":321,"percentile":325},"2025-11-09",{"date":337,"score":279,"percentile":338},"2025-11-10",0.69025,{"date":340,"score":279,"percentile":341},"2025-11-11",0.69035,{"date":343,"score":279,"percentile":344},"2025-11-12",0.69058,{"date":346,"score":279,"percentile":347},"2025-11-13",0.69065,{"date":349,"score":279,"percentile":350},"2025-11-14",0.69074,{"date":352,"score":279,"percentile":353},"2025-11-15",0.69071,{"date":355,"score":279,"percentile":356},"2025-11-16",0.69067,{"date":358,"score":279,"percentile":347},"2025-11-17",{"date":360,"score":279,"percentile":361},"2025-11-18",0.67431,{"date":363,"score":279,"percentile":364},"2025-11-19",0.67436,{"date":366,"score":279,"percentile":367},"2025-11-20",0.6743,{"date":369,"score":279,"percentile":370},"2025-11-21",0.69089,{"date":372,"score":279,"percentile":373},"2025-11-22",0.69085,{"date":375,"score":279,"percentile":376},"2025-11-23",0.69075,{"date":378,"score":279,"percentile":379},"2025-11-24",0.69063,{"date":381,"score":279,"percentile":382},"2025-11-25",0.69069,{"date":384,"score":279,"percentile":385},"2025-11-26",0.69076,{"date":387,"score":279,"percentile":388},"2025-11-27",0.69078,{"date":390,"score":279,"percentile":391},"2025-11-28",0.69066,{"date":393,"score":279,"percentile":394},"2025-11-29",0.69056,{"date":396,"score":279,"percentile":397},"2025-11-30",0.69051,{"date":399,"score":279,"percentile":400},"2025-12-01",0.69199,{"date":402,"score":279,"percentile":403},"2025-12-02",0.69207,{"date":405,"score":279,"percentile":406},"2025-12-03",0.69203,{"date":408,"score":279,"percentile":409},"2025-12-04",0.69046,{"date":411,"score":279,"percentile":412},"2025-12-05",0.69062,{"date":414,"score":279,"percentile":356},"2025-12-06",{"date":416,"score":279,"percentile":412},"2025-12-07",{"date":418,"score":279,"percentile":391},"2025-12-08",{"date":420,"score":279,"percentile":421},"2025-12-09",0.69094,{"date":423,"score":279,"percentile":424},"2025-12-10",0.69135,{"date":426,"score":279,"percentile":427},"2025-12-11",0.69157,{"date":429,"score":279,"percentile":430},"2025-12-12",0.69185,{"date":432,"score":279,"percentile":430},"2025-12-13",{"date":434,"score":279,"percentile":435},"2025-12-14",0.69189,{"date":437,"score":279,"percentile":438},"2025-12-15",0.69184,{"date":440,"score":279,"percentile":441},"2025-12-16",0.69193,{"date":443,"score":279,"percentile":444},"2025-12-17",0.69206,{"date":446,"score":279,"percentile":447},"2025-12-18",0.69235,{"date":449,"score":279,"percentile":450},"2025-12-19",0.69252,{"date":452,"score":279,"percentile":453},"2025-12-20",0.69251,{"date":455,"score":279,"percentile":447},"2025-12-21",{"date":457,"score":279,"percentile":458},"2025-12-22",0.69238,{"date":460,"score":279,"percentile":461},"2025-12-23",0.69237,{"date":463,"score":279,"percentile":464},"2025-12-24",0.69244,{"date":466,"score":279,"percentile":467},"2025-12-25",0.6927,{"date":469,"score":279,"percentile":467},"2025-12-26",{"date":471,"score":279,"percentile":472},"2025-12-27",0.69314,{"date":474,"score":279,"percentile":464},"2025-12-28",{"date":476,"score":279,"percentile":458},"2025-12-29",{"date":478,"score":279,"percentile":453},"2025-12-30",{"date":480,"score":279,"percentile":481},"2025-12-31",0.69268,{"date":483,"score":279,"percentile":484},"2026-01-01",0.69437,{"date":486,"score":279,"percentile":487},"2026-01-02",0.69428,{"date":489,"score":279,"percentile":490},"2026-01-03",0.69427,{"date":492,"score":279,"percentile":493},"2026-01-04",0.69272,{"date":495,"score":279,"percentile":496},"2026-01-05",0.69258,{"date":498,"score":279,"percentile":467},"2026-01-06",{"date":500,"score":279,"percentile":501},"2026-01-07",0.69284,{"date":503,"score":279,"percentile":504},"2026-01-08",0.693,{"date":506,"score":279,"percentile":507},"2026-01-09",0.69307,{"date":509,"score":279,"percentile":507},"2026-01-10",{"date":511,"score":279,"percentile":512},"2026-01-11",0.69298,{"date":514,"score":279,"percentile":515},"2026-01-12",0.69291,{"date":517,"score":279,"percentile":518},"2026-01-13",0.69289,{"date":520,"score":279,"percentile":521},"2026-01-14",0.69319,{"date":523,"score":279,"percentile":524},"2026-01-15",0.69323,{"date":526,"score":279,"percentile":527},"2026-01-16",0.69339,{"date":529,"score":279,"percentile":530},"2026-01-17",0.6933,{"date":532,"score":279,"percentile":533},"2026-01-18",0.69316,{"date":535,"score":279,"percentile":536},"2026-01-19",0.69308,{"date":538,"score":279,"percentile":539},"2026-01-20",0.69317,{"date":541,"score":279,"percentile":542},"2026-01-21",0.69325,{"date":544,"score":279,"percentile":545},"2026-01-22",0.69335,{"date":547,"score":279,"percentile":548},"2026-01-23",0.69364,{"date":550,"score":279,"percentile":551},"2026-01-24",0.69371,{"date":553,"score":279,"percentile":554},"2026-01-25",0.69343,{"date":556,"score":279,"percentile":527},"2026-01-26",{"date":558,"score":279,"percentile":554},"2026-01-27",{"date":560,"score":279,"percentile":561},"2026-01-28",0.69356,{"date":563,"score":279,"percentile":564},"2026-01-29",0.69353,{"date":566,"score":279,"percentile":567},"2026-01-30",0.69361,{"date":569,"score":279,"percentile":570},"2026-01-31",0.69366,{"date":572,"score":279,"percentile":573},"2026-02-01",0.69506,[575,585],{"source":283,"cvss_v2_0":576,"cvss_v3_0":581,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":577,"baseSeverity":9,"vectorString":578,"impactScore":579,"exploitabilityScore":580},6.5,"AV:N/AC:L/Au:S/C:P/I:P/A:P",6.4,8,{"baseScore":281,"baseSeverity":582,"vectorString":284,"impactScore":583,"exploitabilityScore":584},"HIGH",9.8,7.2,{"source":290,"cvss_v2_0":9,"cvss_v3_0":586,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":281,"baseSeverity":9,"vectorString":284,"impactScore":583,"exploitabilityScore":584},[588,600,612],{"ecosystem":9,"name":589,"vendor":590,"product":591,"cpe_part":592,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":593},"script security","jenkins","script_security","a",[594],{"version":595,"is_range":596,"range_type":597,"version_start":9,"version_start_type":9,"version_end":598,"version_end_type":599,"fixed_in":9},"lte1.47",true,"cpe","1.47","including",{"ecosystem":601,"name":602,"vendor":603,"product":604,"cpe_part":9,"purl_type":605,"purl_namespace":603,"purl_name":604,"source":9,"versions":606},"Maven","org.jenkins-ci.plugins:script-security","org.jenkins-ci.plugins","script-security","maven",[607],{"version":608,"is_range":596,"range_type":609,"version_start":9,"version_start_type":9,"version_end":610,"version_end_type":611,"fixed_in":9},"lt1_48","ecosystem","1.48","excluding",{"ecosystem":9,"name":613,"vendor":614,"product":615,"cpe_part":592,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":616},"openshift container platform","redhat","openshift_container_platform",[617],{"version":618,"is_range":277,"range_type":597,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.11"]