[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2018-1000866":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":264,"aliases":265,"duplicate_of":9,"upstream":267,"downstream":268,"duplicates":271,"related":272,"reserved_at":9,"published_at":273,"modified_at":274,"state":275,"summary":276,"references_raw":285,"kevs":322,"epss":323,"epss_history":326,"metrics":582,"affected":595},"CVE-2018-1000866","A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-269","Improper Privilege Management","The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.","weakness","Draft","Class","Medium",[20,182,260],{"id":21,"name":22,"techniques":23},"CAPEC-122","Privilege Abuse",[24],{"id":25,"name":26,"tactics":27,"countermeasures":34},"T1548","Abuse Elevation Control Mechanism",[28,31],{"id":29,"name":30},"TA0030","Defense Evasion",{"id":32,"name":33},"TA0111","Privilege Escalation",[35,40,44,48,52,57,61,65,69,73,77,81,85,89,94,98,103,108,112,116,120,125,129,133,137,141,146,150,154,158,162,166,170,174,178],{"id":36,"name":37,"tactic":38},"D3-CI","Configuration Inventory",{"name":39},"Model",{"id":41,"name":42,"tactic":43},"D3-AM","Access Modeling",{"name":39},{"id":45,"name":46,"tactic":47},"D3-DI","Data Inventory",{"name":39},{"id":49,"name":50,"tactic":51},"D3-NTPM","Network Traffic Policy Mapping",{"name":39},{"id":53,"name":54,"tactic":55},"D3-AEM","Application Exception Monitoring",{"name":56},"Detect",{"id":58,"name":59,"tactic":60},"D3-SCA","System Call Analysis",{"name":56},{"id":62,"name":63,"tactic":64},"D3-SFA","System File Analysis",{"name":56},{"id":66,"name":67,"tactic":68},"D3-FA","File Analysis",{"name":56},{"id":70,"name":71,"tactic":72},"D3-FIM","File Integrity Monitoring",{"name":56},{"id":74,"name":75,"tactic":76},"D3-OPM","Operational Process Monitoring",{"name":56},{"id":78,"name":79,"tactic":80},"D3-DA","Dynamic Analysis",{"name":56},{"id":82,"name":83,"tactic":84},"D3-EFA","Emulated File Analysis",{"name":56},{"id":86,"name":87,"tactic":88},"D3-PSA","Process Spawn Analysis",{"name":56},{"id":90,"name":91,"tactic":92},"D3-FEV","File Eviction",{"name":93},"Evict",{"id":95,"name":96,"tactic":97},"D3-AL","Account Locking",{"name":93},{"id":99,"name":100,"tactic":101},"D3-DF","Decoy File",{"name":102},"Deceive",{"id":104,"name":105,"tactic":106},"D3-FE","File Encryption",{"name":107},"Harden",{"id":109,"name":110,"tactic":111},"D3-AA","Agent Authentication",{"name":107},{"id":113,"name":114,"tactic":115},"D3-CDP","Change Default Password",{"name":107},{"id":117,"name":118,"tactic":119},"D3-SCP","System Configuration Permissions",{"name":107},{"id":121,"name":122,"tactic":123},"D3-RC","Restore Configuration",{"name":124},"Restore",{"id":126,"name":127,"tactic":128},"D3-RF","Restore File",{"name":124},{"id":130,"name":131,"tactic":132},"D3-ULA","Unlock Account",{"name":124},{"id":134,"name":135,"tactic":136},"D3-RUAA","Restore User Account Access",{"name":124},{"id":138,"name":139,"tactic":140},"D3-RD","Restore Database",{"name":124},{"id":142,"name":143,"tactic":144},"D3-SCF","System Call Filtering",{"name":145},"Isolate",{"id":147,"name":148,"tactic":149},"D3-CF","Content Filtering",{"name":145},{"id":151,"name":152,"tactic":153},"D3-LFP","Local File Permissions",{"name":145},{"id":155,"name":156,"tactic":157},"D3-RFAM","Remote File Access Mediation",{"name":145},{"id":159,"name":160,"tactic":161},"D3-CQ","Content Quarantine",{"name":145},{"id":163,"name":164,"tactic":165},"D3-CM","Content Modification",{"name":145},{"id":167,"name":168,"tactic":169},"D3-UAP","User Account Permissions",{"name":145},{"id":171,"name":172,"tactic":173},"D3-EAL","Executable Allowlisting",{"name":145},{"id":175,"name":176,"tactic":177},"D3-EDL","Executable Denylisting",{"name":145},{"id":179,"name":180,"tactic":181},"D3-HBPI","Hardware-based Process Isolation",{"name":145},{"id":183,"name":33,"techniques":184},"CAPEC-233",[185],{"id":25,"name":26,"tactics":186,"countermeasures":189},[187,188],{"id":29,"name":30},{"id":32,"name":33},[190,192,194,196,198,200,202,204,206,208,210,212,214,216,218,220,222,224,226,228,230,232,234,236,238,240,242,244,246,248,250,252,254,256,258],{"id":36,"name":37,"tactic":191},{"name":39},{"id":41,"name":42,"tactic":193},{"name":39},{"id":45,"name":46,"tactic":195},{"name":39},{"id":49,"name":50,"tactic":197},{"name":39},{"id":53,"name":54,"tactic":199},{"name":56},{"id":58,"name":59,"tactic":201},{"name":56},{"id":62,"name":63,"tactic":203},{"name":56},{"id":66,"name":67,"tactic":205},{"name":56},{"id":70,"name":71,"tactic":207},{"name":56},{"id":74,"name":75,"tactic":209},{"name":56},{"id":78,"name":79,"tactic":211},{"name":56},{"id":82,"name":83,"tactic":213},{"name":56},{"id":86,"name":87,"tactic":215},{"name":56},{"id":90,"name":91,"tactic":217},{"name":93},{"id":95,"name":96,"tactic":219},{"name":93},{"id":99,"name":100,"tactic":221},{"name":102},{"id":104,"name":105,"tactic":223},{"name":107},{"id":109,"name":110,"tactic":225},{"name":107},{"id":113,"name":114,"tactic":227},{"name":107},{"id":117,"name":118,"tactic":229},{"name":107},{"id":121,"name":122,"tactic":231},{"name":124},{"id":126,"name":127,"tactic":233},{"name":124},{"id":130,"name":131,"tactic":235},{"name":124},{"id":134,"name":135,"tactic":237},{"name":124},{"id":138,"name":139,"tactic":239},{"name":124},{"id":142,"name":143,"tactic":241},{"name":145},{"id":147,"name":148,"tactic":243},{"name":145},{"id":151,"name":152,"tactic":245},{"name":145},{"id":155,"name":156,"tactic":247},{"name":145},{"id":159,"name":160,"tactic":249},{"name":145},{"id":163,"name":164,"tactic":251},{"name":145},{"id":167,"name":168,"tactic":253},{"name":145},{"id":171,"name":172,"tactic":255},{"name":145},{"id":175,"name":176,"tactic":257},{"name":145},{"id":179,"name":180,"tactic":259},{"name":145},{"id":261,"name":262,"techniques":263},"CAPEC-58","Restful Privilege Elevation",[],[],[266],"GHSA-gqhm-4h93-rrhg",[],[269],{"_key":270},"RHBA-2019:0326",[],[],"2018-12-10T14:00:00.000Z","2024-08-05T12:47:56.163Z","Modified",{"cisa_kev":277,"cisa_ransomware":277,"cisa_vendor":9,"epss_severity":278,"epss_score":279,"severity":280,"severity_score":281,"severity_version":282,"severity_source":283,"severity_vector":284,"severity_status":275},false,"low",0.00615,"high",8.8,"v3.0","nvd","CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[286,295,301,305,310,314,318],{"url":287,"sources":288,"tags":291},"https://jenkins.io/security/advisory/2018-10-29/#SECURITY-1186",[289,283,290],"cve.org","osv_maven",[292,293,294],"X Refsource CONFIRM","Vendor Advisory","WEB",{"url":296,"sources":297,"tags":298},"https://access.redhat.com/errata/RHBA-2019:0326",[289,283,290],[293,299,300,294],"X Refsource REDHAT","Third Party Advisory",{"url":302,"sources":303,"tags":304},"https://access.redhat.com/errata/RHBA-2019:0327",[289,283,290],[293,299,300,294],{"url":306,"sources":307,"tags":308},"https://nvd.nist.gov/vuln/detail/CVE-2018-1000866",[290],[309],"Advisory",{"url":311,"sources":312,"tags":313},"https://github.com/jenkinsci/script-security-plugin/commit/16c862ae9d4038a3edbd8bdfb0fd1401a509d56b",[290],[294],{"url":315,"sources":316,"tags":317},"https://github.com/jenkinsci/workflow-cps-plugin/commit/0eb89aaf24065dbbdf6db84516ac1a52cd435e6d",[290],[294],{"url":319,"sources":320,"tags":321},"https://github.com/jenkinsci/workflow-cps-plugin/commit/e1c56eb6d85d513cb24dfe188e6f592d0ff84b38",[290],[294],[],{"date":324,"score":279,"percentile":325},"2026-06-04",0.70277,[327,331,334,337,340,342,344,347,350,353,356,359,362,365,367,370,373,376,379,382,385,388,391,394,397,400,403,406,409,412,415,418,421,423,425,427,430,433,436,439,441,444,447,450,453,456,459,462,464,467,470,473,476,478,481,483,485,487,490,493,496,499,502,505,507,510,513,516,518,521,524,527,530,533,536,539,542,545,548,551,554,557,560,563,565,567,570,573,576,579],{"date":328,"score":329,"percentile":330},"2025-11-04",0.00639,0.6971,{"date":332,"score":329,"percentile":333},"2025-11-05",0.69695,{"date":335,"score":329,"percentile":336},"2025-11-06",0.69693,{"date":338,"score":329,"percentile":339},"2025-11-07",0.69705,{"date":341,"score":329,"percentile":339},"2025-11-08",{"date":343,"score":329,"percentile":333},"2025-11-09",{"date":345,"score":279,"percentile":346},"2025-11-10",0.69025,{"date":348,"score":279,"percentile":349},"2025-11-11",0.69035,{"date":351,"score":279,"percentile":352},"2025-11-12",0.69058,{"date":354,"score":279,"percentile":355},"2025-11-13",0.69065,{"date":357,"score":279,"percentile":358},"2025-11-14",0.69074,{"date":360,"score":279,"percentile":361},"2025-11-15",0.69071,{"date":363,"score":279,"percentile":364},"2025-11-16",0.69067,{"date":366,"score":279,"percentile":355},"2025-11-17",{"date":368,"score":279,"percentile":369},"2025-11-18",0.67431,{"date":371,"score":279,"percentile":372},"2025-11-19",0.67436,{"date":374,"score":279,"percentile":375},"2025-11-20",0.6743,{"date":377,"score":279,"percentile":378},"2025-11-21",0.69089,{"date":380,"score":279,"percentile":381},"2025-11-22",0.69085,{"date":383,"score":279,"percentile":384},"2025-11-23",0.69075,{"date":386,"score":279,"percentile":387},"2025-11-24",0.69063,{"date":389,"score":279,"percentile":390},"2025-11-25",0.69069,{"date":392,"score":279,"percentile":393},"2025-11-26",0.69076,{"date":395,"score":279,"percentile":396},"2025-11-27",0.69078,{"date":398,"score":279,"percentile":399},"2025-11-28",0.69066,{"date":401,"score":279,"percentile":402},"2025-11-29",0.69056,{"date":404,"score":279,"percentile":405},"2025-11-30",0.69051,{"date":407,"score":279,"percentile":408},"2025-12-01",0.69199,{"date":410,"score":279,"percentile":411},"2025-12-02",0.69207,{"date":413,"score":279,"percentile":414},"2025-12-03",0.69203,{"date":416,"score":279,"percentile":417},"2025-12-04",0.69046,{"date":419,"score":279,"percentile":420},"2025-12-05",0.69062,{"date":422,"score":279,"percentile":364},"2025-12-06",{"date":424,"score":279,"percentile":420},"2025-12-07",{"date":426,"score":279,"percentile":399},"2025-12-08",{"date":428,"score":279,"percentile":429},"2025-12-09",0.69094,{"date":431,"score":279,"percentile":432},"2025-12-10",0.69135,{"date":434,"score":279,"percentile":435},"2025-12-11",0.69157,{"date":437,"score":279,"percentile":438},"2025-12-12",0.69185,{"date":440,"score":279,"percentile":438},"2025-12-13",{"date":442,"score":279,"percentile":443},"2025-12-14",0.69189,{"date":445,"score":279,"percentile":446},"2025-12-15",0.69184,{"date":448,"score":279,"percentile":449},"2025-12-16",0.69193,{"date":451,"score":279,"percentile":452},"2025-12-17",0.69206,{"date":454,"score":279,"percentile":455},"2025-12-18",0.69235,{"date":457,"score":279,"percentile":458},"2025-12-19",0.69252,{"date":460,"score":279,"percentile":461},"2025-12-20",0.69251,{"date":463,"score":279,"percentile":455},"2025-12-21",{"date":465,"score":279,"percentile":466},"2025-12-22",0.69238,{"date":468,"score":279,"percentile":469},"2025-12-23",0.69237,{"date":471,"score":279,"percentile":472},"2025-12-24",0.69244,{"date":474,"score":279,"percentile":475},"2025-12-25",0.6927,{"date":477,"score":279,"percentile":475},"2025-12-26",{"date":479,"score":279,"percentile":480},"2025-12-27",0.69314,{"date":482,"score":279,"percentile":472},"2025-12-28",{"date":484,"score":279,"percentile":466},"2025-12-29",{"date":486,"score":279,"percentile":461},"2025-12-30",{"date":488,"score":279,"percentile":489},"2025-12-31",0.69268,{"date":491,"score":279,"percentile":492},"2026-01-01",0.69437,{"date":494,"score":279,"percentile":495},"2026-01-02",0.69428,{"date":497,"score":279,"percentile":498},"2026-01-03",0.69427,{"date":500,"score":279,"percentile":501},"2026-01-04",0.69272,{"date":503,"score":279,"percentile":504},"2026-01-05",0.69258,{"date":506,"score":279,"percentile":475},"2026-01-06",{"date":508,"score":279,"percentile":509},"2026-01-07",0.69284,{"date":511,"score":279,"percentile":512},"2026-01-08",0.693,{"date":514,"score":279,"percentile":515},"2026-01-09",0.69307,{"date":517,"score":279,"percentile":515},"2026-01-10",{"date":519,"score":279,"percentile":520},"2026-01-11",0.69298,{"date":522,"score":279,"percentile":523},"2026-01-12",0.69291,{"date":525,"score":279,"percentile":526},"2026-01-13",0.69289,{"date":528,"score":279,"percentile":529},"2026-01-14",0.69319,{"date":531,"score":279,"percentile":532},"2026-01-15",0.69323,{"date":534,"score":279,"percentile":535},"2026-01-16",0.69339,{"date":537,"score":279,"percentile":538},"2026-01-17",0.6933,{"date":540,"score":279,"percentile":541},"2026-01-18",0.69316,{"date":543,"score":279,"percentile":544},"2026-01-19",0.69308,{"date":546,"score":279,"percentile":547},"2026-01-20",0.69317,{"date":549,"score":279,"percentile":550},"2026-01-21",0.69325,{"date":552,"score":279,"percentile":553},"2026-01-22",0.69335,{"date":555,"score":279,"percentile":556},"2026-01-23",0.69364,{"date":558,"score":279,"percentile":559},"2026-01-24",0.69371,{"date":561,"score":279,"percentile":562},"2026-01-25",0.69343,{"date":564,"score":279,"percentile":535},"2026-01-26",{"date":566,"score":279,"percentile":562},"2026-01-27",{"date":568,"score":279,"percentile":569},"2026-01-28",0.69356,{"date":571,"score":279,"percentile":572},"2026-01-29",0.69353,{"date":574,"score":279,"percentile":575},"2026-01-30",0.69361,{"date":577,"score":279,"percentile":578},"2026-01-31",0.69366,{"date":580,"score":279,"percentile":581},"2026-02-01",0.69506,[583,593],{"source":283,"cvss_v2_0":584,"cvss_v3_0":589,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":585,"baseSeverity":9,"vectorString":586,"impactScore":587,"exploitabilityScore":588},6.5,"AV:N/AC:L/Au:S/C:P/I:P/A:P",6.4,8,{"baseScore":281,"baseSeverity":590,"vectorString":284,"impactScore":591,"exploitabilityScore":592},"HIGH",9.8,7.2,{"source":290,"cvss_v2_0":9,"cvss_v3_0":594,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":281,"baseSeverity":9,"vectorString":284,"impactScore":591,"exploitabilityScore":592},[596,609,617],{"ecosystem":597,"name":598,"vendor":599,"product":600,"cpe_part":9,"purl_type":601,"purl_namespace":599,"purl_name":600,"source":9,"versions":602},"Maven","org.jenkins-ci.plugins:script-security","org.jenkins-ci.plugins","script-security","maven",[603],{"version":604,"is_range":605,"range_type":606,"version_start":9,"version_start_type":9,"version_end":607,"version_end_type":608,"fixed_in":9},"lt1_48",true,"ecosystem","1.48","excluding",{"ecosystem":597,"name":610,"vendor":611,"product":612,"cpe_part":9,"purl_type":601,"purl_namespace":611,"purl_name":612,"source":9,"versions":613},"org.jenkins-ci.plugins.workflow:workflow-cps","org.jenkins-ci.plugins.workflow","workflow-cps",[614],{"version":615,"is_range":605,"range_type":606,"version_start":9,"version_start_type":9,"version_end":616,"version_end_type":608,"fixed_in":9},"lt2_60","2.60",{"ecosystem":9,"name":618,"vendor":619,"product":620,"cpe_part":621,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":622},"openshift container platform","redhat","openshift_container_platform","a",[623],{"version":624,"is_range":277,"range_type":625,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.11","cpe"]