Jenkins Pipeline Groovy Plugin Vulnerability Affecting Default Parameter Expressions
CVE-2020-2109
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 12 February 2020
What is CVE-2020-2109?
The Jenkins Pipeline: Groovy Plugin, specifically versions 2.78 and earlier, is subject to a vulnerability that allows attackers to bypass sandbox protection via default parameter expressions in CPS-transformed methods. This weakness could enable unauthorized code execution in the Jenkins environment, posing a significant risk to continuous integration and delivery processes. It is crucial for users to review their usage of this plugin and apply necessary updates to mitigate potential threats.
Affected Version(s)
Jenkins Pipeline: Groovy Plugin <= 2.78