SB2020031128 - Multiple vulnerabilities in Jenkins Script Security Plugin
Published: March 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-2134)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Sandbox protection can be circumvented through a crafted constructor calls and bodies. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-2135)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Sandbox protection can be circumvented through a crafted method calls on objects that implement "GroovyInterceptable". A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.
Remediation
Install update from vendor's website.