CVE-2017-2650 describes a critical vulnerability in the Jenkins Pipeline: Classpath Step plugin, allowing a bypass of the Script Security sandbox. This flaw affects Jenkins users with SCM commit access or Job/Configure permissions. With a CVSS score of 8.5 (HIGH), the vulnerability has a network attack vector, high impact on confidentiality, integrity, and availability, but requires high attack complexity. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:jenkins:pipeline_classpath_step:0.1.0:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.