Sandbox Bypass Vulnerability in Script Security Plugin Allows Arbitrary Code Execution

Sandbox Bypass Vulnerability in Script Security Plugin Allows Arbitrary Code Execution

CVE-2019-1003000 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.

Learn more about our Web Application Penetration Testing UK.