CVE-2020-2279

CRITICAL

Jenkins Script Security Plugin <1.74 - RCE

Title source: llm
STIX 2.1

Description

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/09/23/1

Scores

CVSS v3 9.9
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (2)
jenkins/script_security < 1.74
org.jenkins-ci.plugins/script-security 1.67 - 1.75Maven
Published Sep 23, 2020
Tracked Since Feb 18, 2026