#VU47187 Permissions, Privileges, and Access Controls in Script Security - CVE-2020-2279
Published: September 23, 2020 / Updated: September 30, 2020
Script Security
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the sandbox protection bypass in the affected plugin. A remote authenticated attacker can provide a specially crafted return values or script binding content and execute arbitrary code on the Jenkins controller JVM.