PT-2025-14512 · Jenkins · Jenkins Templating Engine Plugin+1

Published

2025-04-02

·

Updated

2025-04-29

·

CVE-2025-31722

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Templating Engine Plugin versions 2.5.3 and earlier
Description The issue allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM, due to libraries defined in folders not being subject to sandbox protection.
Recommendations For Jenkins Templating Engine Plugin versions 2.5.3 and earlier, update to a version that includes the fix for this issue, as no specific workaround is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-03795
CVE-2025-31722
GHSA-4VJP-327P-W4QV

Affected Products

Jenkins
Jenkins Templating Engine Plugin