A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade atomic-openshift-node-problem-detectorUpgrade jenkinsUpgrade atomic-openshift-service-idlerUpgrade openshift-ansibleUpgrade golang-github-openshift-oauth-proxyUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-metrics-serverUpgrade atomic-openshift-web-consoleUpgrade atomic-openshiftUpgrade atomic-openshift-deschedulerUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-dockerregistryUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-cluster-autoscalerUpgrade openshift-enterprise-cluster-capacityUpgrade haproxyUpgrade golang-github-prometheus-prometheusUpgrade jenkins-2-pluginsUpgrade golang-github-prometheus-node_exporter | Mar 15, 2019 | Jan 8, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub