漏洞描述
A sandbox bypass vulnerability exists in the Jenkins Script Security Plugin (versions 1.49 and earlier) within src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java. This flaw allows attackers with permission to submit sandboxed scripts to execute arbitrary code on the Jenkins master JVM, potentially compromising the entire Jenkins environment.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
jenkins.iohttps://jenkins.io/security/advisory/2019-01-08/#SECURITY-1266↗github.comhttps://github.com/slowmistio/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins↗github.comhttps://github.com/1NTheKut/CVE-2019-1003000_RCE-DETECTION↗github.comhttps://github.com/purple-WL/Jenkins_CVE-2019-1003000↗