CVE-2019-16538 PUBLISHED

Reported by jenkins · Published November 21, 2019

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.

Affected Products

VendorProductVersions
Jenkins projectJenkins Script Security Plugin1.67 and earlier
Mavenorg.jenkins-ci.plugins:script-security0, 0
Jenkins projectJenkins Script Security Plugin1.67 and earlier, 1.67 and earlier

Timeline

References

Open in Interactive Console →