#VU21522 Permissions, Privileges, and Access Controls in Script Security - CVE-2019-10431
Published: October 3, 2019
Script Security
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the sandbox protection in the affected plugin can be circumvented through default parameter expressions in constructors. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.