Description
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-784j-h234-m56x | Protection Mechanism Failure in Jenkins Script Security Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-05T03:00:19.257Z
Reserved: 2019-01-22T00:00:00.000Z
Link: CVE-2019-1003000
No data.
Status : Modified
Published: 2019-01-22T14:29:00.267
Modified: 2026-06-17T02:09:30.830
Link: CVE-2019-1003000
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- NVD-CWE-Other
Github GHSA