#VU26004 Permissions, Privileges, and Access Controls in Script Security - CVE-2020-2134
Published: March 11, 2020
Script Security
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Sandbox protection can be circumvented through a crafted constructor calls and bodies. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.