CVE-2020-2110

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/02/2020
Last modified:
25/10/2023

Description

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:* 1.69 (including)