Description
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
Remediation
References
http://www.securityfocus.com/bid/107295
https://access.redhat.com/errata/RHSA-2019:0739
https://jenkins.io/security/advisory/2019-02-19/#SECURITY-1320
Related Vulnerabilities
CVE-2020-7619 Vulnerability in npm package get-git-data
CVE-2020-7780 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.12
CVE-2019-1003091 Vulnerability in maven package com.soasta.jenkins:cloudtest
CVE-2018-12545 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-jdk15to18