Permissions, Privileges, and Access Controls in Script Security - CVE-2020-2134
Published: March 11, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Sandbox protection can be circumvented through a crafted constructor calls and bodies. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.
Affected software
jenkins-2-plugins (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-2134
jenkins-2-plugins (Red Hat package) - addressed in versions 3.11.1591354111-1.el7, 4.3.1597915133-1.el7, 4.4.1592817009-1.el7