Executive brief
A sandbox bypass vulnerability in the Jenkins Script Security Plugin allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. The flaw exists in the GroovySandbox.java and SecureGroovyScript.java components due to a protection mechanism failure.
Affected products
- Jenkins Project Script Security Plugin 1.53 and earlier
Timeline
- 2019-03-06: disclosed: Vendor advisory SECURITY-1336 published.
- 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-04-25: advisory: NVD publication date.