#VU21569 Improper access control in Script Security - CVE-2019-1003024
Published: October 7, 2019
Script Security
Jenkins
Description
The vulnerability allows a remote attacker to bypass sandbox restrictions.
The vulnerability exists due to improper access restrictions in "RejectASTTransformsCustomizer.java". A remote authenticated attacker with Overall/Read permission, or the ability to control Jenkins file or sandboxed Pipeline shared library contents in SCM, can provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.