Description
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/11/21/1
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1658
Related Vulnerabilities
CVE-2019-9843 Vulnerability in maven package com.diffplug.spotless:spotless-maven-plugin
CVE-2022-39386 Vulnerability in npm package fastify-websocket
CVE-2019-6284 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-36897 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage