CRITICAL9.9
GHSA-r6mc-mrvr-23cr
Sandbox bypass in Jenkins Pipeline: Groovy Plugin
Quick fix
GHSA-r6mc-mrvr-23cr — org.jenkins-ci.plugins.workflow:workflow-cps: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.64</version> for org.jenkins-ci.plugins.workflow:workflow-cpsDetails
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.plugins.workflow:workflow-cps
Introduced in:
0Fixed in: 2.64Fix
# pom.xml: bump <version>2.64</version> for org.jenkins-ci.plugins.workflow:workflow-cpsReferences
- https://nvd.nist.gov/vuln/detail/CVE-2019-1003030[ADVISORY]
- https://access.redhat.com/errata/RHSA-2019:0739[WEB]
- https://github.com/jenkinsci/workflow-cps-plugin[PACKAGE]
- https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1336%20(2)[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1003030[WEB]
- http://packetstormsecurity.com/files/159603/Jenkins-2.63-Sandbox-Bypass.html[WEB]