#VU26005 Permissions, Privileges, and Access Controls in Script Security - CVE-2020-2135
Published: March 11, 2020
Script Security
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Sandbox protection can be circumvented through a crafted method calls on objects that implement "GroovyInterceptable". A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.