Sandbox Bypass Affecting org.jenkins-ci.plugins:script-security package, versions [,1.70)
Threat Intelligence
EPSS
0.11% (45th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGJENKINSCIPLUGINS-548688
- published 13 Feb 2020
- disclosed 12 Feb 2020
- credit Nils Emmerich of ERNW Research GmbH
Introduced: 12 Feb 2020
CVE-2020-2110 Open this link in a new tabHow to fix?
Upgrade org.jenkins-ci.plugins:script-security
to version 1.70 or higher.
Overview
org.jenkins-ci.plugins:script-security is a package that allows Jenkins administrators to control what in-process scripts can be run by less-privileged users.
Affected versions of this package are vulnerable to Sandbox Bypass. Sandbox protection in Jenkins Script Security Plugin could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
References
CVSS Scores
version 3.1