CyberRota Analysis
AI-GeneratedThe Jenkins Script Security Plugin versions up to 1412.v7737b_3405f86 are vulnerable due to improper use of the `@DataBoundConstructor` annotation, which permits unauthorized attackers to read sensitive script approval configurations by submitting specific forms. This exposure could lead to unauthorized access to script execution settings, potentially compromising the integrity of Jenkins environments. Organizations using Jenkins, particularly those with sensitive scripts or configurations, should prioritize patching this vulnerability to mitigate risks.
Original NVD Description
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.