CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass

CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-1003000: Jenkins Script Security PluGin <=1.49 – Sandbox Bypass

漏洞描述

A sandbox bypass vulnerability exists in the Jenkins Script Security Plugin (versions 1.49 and earlier) within src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java. This flaw allows attackers with permission to submit sandboxed scripts to execute arbitrary code on the Jenkins master JVM, potentially compromising the entire Jenkins environment.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享