SB2019020621 - Sandbox restrictions bypass in Script Security plugin for Jenkins
Published: February 6, 2019 Updated: October 7, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2019-1003005)
The vulnerability allows a remote attacker to bypass sandbox restrictions.
The vulnerability exists due to improper access restrictions in "src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java". A remote authenticated attacker with Overall/Read permission can provide a Groovy script to an HTTP endpoint execute arbitrary code on the Jenkins master JVM.
Remediation
Install update from vendor's website.