CVE-2019-16538

HIGH

Jenkins Script Security Plugin <1.67 - RCE

Title source: llm
STIX 2.1

Description

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/11/21/1

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 38.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (2)
jenkins/script_security < 1.67
org.jenkins-ci.plugins/script-security 0 - 1.68Maven
Published Nov 21, 2019
Tracked Since Feb 18, 2026