CVE-2026-57301
Jenkins Project Jenkins OWASP ZAP Plugin, official owasp zap 취약점
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
- 대응 우선순위
- 점검
- CVSS
- 8.8
- EPSS
- 0.42% 백분위 34.1% · 2026.07.20 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.24