GHSA-fm3j-r98g-97jh
HIGHCVE-2019-1003033A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. Groovy Plugin 2.2 uses Script Security APIs that apply sandbox protection during these phases.
- Affected
- <= 2.1
- Fixed in
- 2.2
- Published
- 2022-05-13
- Source
- github