Description
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/11/21/1
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1658
Related Vulnerabilities
CVE-2022-31103 Vulnerability in npm package lettersanitizer
CVE-2019-10378 Vulnerability in maven package org.jenkins-ci.plugins:testlink
CVE-2021-44550 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2020-2226 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project