Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5034 | Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable. |
Github GHSA |
GHSA-qvhf-3567-pc4v | Sandbox bypass vulnerability in Script Security Plugin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T07:01:41.104Z
Reserved: 2019-12-05T00:00:00.000Z
Link: CVE-2020-2135
No data.
Status : Modified
Published: 2020-03-09T16:15:12.703
Modified: 2024-11-21T05:24:45.250
Link: CVE-2020-2135
OpenCVE Enrichment
No data.
EUVD
Github GHSA