Description
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/10/01/2
https://access.redhat.com/errata/RHSA-2019:4055
https://access.redhat.com/errata/RHSA-2019:4089
https://access.redhat.com/errata/RHSA-2019:4097
https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579
Related Vulnerabilities
CVE-2020-1936 Vulnerability in maven package org.apache.ambari:ambari-web
CVE-2019-10414 Vulnerability in maven package de.wellnerbou.jenkins:git-changelog
CVE-2019-10061 Vulnerability in npm package opencv
CVE-2019-1003064 Vulnerability in maven package org.jenkins-ci.plugins:aws-device-farm
CVE-2020-2222 Vulnerability in maven package org.jenkins-ci.main:jenkins-core