CVE-2018-1000865: High severity jenkins script security vulnerability
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000865?
CVE-2018-1000865 is considered a critical vulnerability as it allows attackers to execute arbitrary code on the Jenkins master JVM.
How do I fix CVE-2018-1000865?
To fix CVE-2018-1000865, upgrade the Script Security Plugin to version 1.48 or later.
Who is affected by CVE-2018-1000865?
CVE-2018-1000865 affects Jenkins installations using Script Security Plugin versions 1.47 and earlier.
What permissions are required to exploit CVE-2018-1000865?
An attacker needs Job/Configure permission to exploit CVE-2018-1000865.
Which software components are involved in CVE-2018-1000865?
CVE-2018-1000865 primarily involves the Script Security Plugin in Jenkins.