CVE-2020-2109: Input Validation
Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.plugins.workflow:workflow-cpsto a version that resolves this vulnerability.Fixed in 2.79
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2109?
CVE-2020-2109 is classified as a medium severity vulnerability.
How do I fix CVE-2020-2109?
To fix CVE-2020-2109, upgrade the Groovy Plugin in Jenkins Pipeline to version 2.79 or later.
What impact does CVE-2020-2109 have on Jenkins users?
CVE-2020-2109 allows circumvention of sandbox protection in Jenkins Pipeline, potentially leading to unauthorized code execution.
Which versions of Jenkins are affected by CVE-2020-2109?
Jenkins Pipeline: Groovy Plugin versions up to and including 2.78 are affected by CVE-2020-2109.
Why is it important to address CVE-2020-2109?
Addressing CVE-2020-2109 is important to maintain security and prevent attackers from exploiting the sandbox bypass.