← Zuruck zu CVEs
CVE-2020-2135
HIGH8.8
Beschreibung
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/9/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
jenkins:script_security
Schwachen (CWE)
CWE-863
Referenzen
http://www.openwall.com/lists/oss-security/2020/03/09/1(jenkinsci-cert@googlegroups.com)
https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1754(jenkinsci-cert@googlegroups.com)
http://www.openwall.com/lists/oss-security/2020/03/09/1(af854a3a-2127-422b-91ae-364da2661108)
https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1754(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.