GHSA-r6mc-mrvr-23cr
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2019-1003030, https://access.redhat.com/errata/RHSA-2019:0739, https://github.com/jenkinsci/workflow-cps-plugin, https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1336%20(2), https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1003030, http://packetstormsecurity.com/files/159603/Jenkins-2.63-Sandbox-Bypass.html
