Description
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.
Remediation
References
http://www.securityfocus.com/bid/96981
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2017-7678 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2019-16571 Vulnerability in maven package org.jenkins-ci.plugins:rapiddeploy-jenkins
CVE-2017-1000387 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2021-40660 Vulnerability in maven package org.javadelight:delight-nashorn-sandbox
CVE-2016-5394 Vulnerability in maven package org.apache.sling:org.apache.sling.xss