First published: Wed Feb 12 2020(Updated: )
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:script-security | <=1.69 | 1.70 |
Jenkins Script Security | <=1.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-2110 is high with a CVSS score of 8.8.
The sandbox protection can be circumvented by applying AST transforming annotations to imports or by using them inside of other annotations during the script compilation phase.