Jenkins Script Security Plugin 1189.vbab_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
{
"cpe": "cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1190.v65867a_a_47126"
}
],
"source": "CPE_RANGE"
}