Executive brief
A sandbox bypass vulnerability in the Jenkins Pipeline: Groovy Plugin allows attackers who can control pipeline scripts to execute arbitrary code on the Jenkins master JVM. This occurs due to improper sandbox restrictions in CpsGroovyShell.java, leading to remote code execution.
Affected products
- Jenkins Pipeline: Groovy Plugin 2.63 and earlier
- Jenkins Matrix Project Plugin (none specified)
Timeline
- 2019-03-06: advisory: Vendor security advisory published by Jenkins.
- 2019-03-12: disclosed: Initial NVD analysis.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.