Jenkins Script Security Plugin Sandbox Circumvention Vulnerability
CVE-2020-2135

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
9 March 2020

Summary

The Jenkins Script Security Plugin, versions 1.70 and earlier, is subject to a vulnerability that enables the circumvention of sandbox protection mechanisms. This flaw arises when crafted method calls are made on objects implementing GroovyInterceptable, potentially allowing unauthorized script execution in a Jenkins environment. This could lead to elevation of privileges for an attacker. Organizations using this plugin should update to the latest versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Jenkins Script Security Plugin <= 1.70

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.