CVE-2018-1000866: High severity jenkins pipeline vulnerability
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000866?
CVE-2018-1000866 is classified as a high severity vulnerability due to its potential for unauthorized access and sandbox bypass.
How do I fix CVE-2018-1000866?
To fix CVE-2018-1000866, upgrade the Pipeline: Groovy Plugin to version 2.60 or later.
What systems are affected by CVE-2018-1000866?
CVE-2018-1000866 affects Jenkins Pipeline version 2.59 and earlier, as well as Red Hat OpenShift Container Platform version 3.11.
Who can exploit CVE-2018-1000866?
Any user with Job/Configure permission can exploit CVE-2018-1000866 to bypass the established security sandbox.
What type of vulnerability is CVE-2018-1000866?
CVE-2018-1000866 is a sandbox bypass vulnerability.