{"id":"GHSA-gqhm-4h93-rrhg","summary":"Jenkins Script Security and Pipeline Groovy Plugins Sandbox Bypass","details":"A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM","aliases":["CVE-2018-1000866"],"modified":"2024-01-09T18:57:04.743978Z","published":"2022-05-13T01:48:40Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-09T18:30:37Z","nvd_published_at":"2018-12-10T14:29:00Z","cwe_ids":["CWE-269"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000866"},{"type":"WEB","url":"https://github.com/jenkinsci/script-security-plugin/commit/16c862ae9d4038a3edbd8bdfb0fd1401a509d56b"},{"type":"WEB","url":"https://github.com/jenkinsci/workflow-cps-plugin/commit/0eb89aaf24065dbbdf6db84516ac1a52cd435e6d"},{"type":"WEB","url":"https://github.com/jenkinsci/workflow-cps-plugin/commit/e1c56eb6d85d513cb24dfe188e6f592d0ff84b38"},{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2019:0326"},{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2019:0327"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2018-10-29/#SECURITY-1186"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins.workflow:workflow-cps","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins.workflow/workflow-cps"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.60"}]}],"versions":["0.1-beta-1","0.1-beta-2","0.1-beta-3","0.1-beta-4","0.1-beta-5","0.1-beta-6","0.1-beta-7","0.1-beta-8","1.0","1.0-beta-1","1.1","1.10","1.10-beta-1","1.10.1","1.11","1.11-beta-1","1.11-beta-2","1.11-beta-3","1.11-beta-4","1.12","1.12-beta-1","1.12-beta-2","1.12-beta-3","1.13","1.14","1.14-beta-1","1.14.1","1.14.1-beta-1","1.14.2","1.15","1.15-beta-1","1.2","1.3","1.4","1.4.1","1.4.2","1.4.3","1.4.3-beta-1","1.5","1.6","1.6-alpha-1","1.7","1.7-alpha-1","1.8","1.9","1.9-beta-1","2.0","2.1","2.10","2.11","2.12","2.13","2.14","2.15","2.16","2.17","2.18","2.19","2.2","2.20","2.21","2.22","2.23","2.24","2.25","2.26","2.27","2.28","2.29","2.3","2.30","2.30-stepstorage2-alpha","2.30-stepstorage2-alpha2","2.30-stepstorage4-beta","2.31","2.32","2.33","2.34","2.35","2.36","2.36.1","2.37","2.38","2.39","2.4","2.40","2.41","2.42","2.43","2.43-durability-beta-1","2.43-durability-beta-2","2.43-durability-beta-3","2.43-durability-beta-4","2.44","2.45","2.46","2.46.1","2.46.2","2.47","2.48","2.49","2.5","2.50","2.51","2.52","2.53","2.54","2.54.1","2.54.2","2.55","2.56","2.57","2.57.1","2.57.2","2.57.3","2.58","2.58-beta-1","2.59","2.6","2.7","2.8","2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json"}},{"package":{"name":"org.jenkins-ci.plugins:script-security","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/script-security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.48"}]}],"versions":["1.0","1.0-beta-1","1.0-beta-2","1.0-beta-3","1.0-beta-4","1.0-beta-5","1.0-beta-6","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16","1.17","1.18","1.18.1","1.19","1.2","1.20","1.21","1.22","1.23","1.24","1.25","1.26","1.27","1.28","1.29","1.29.1","1.3","1.30","1.31","1.33","1.34","1.35","1.36","1.37","1.38","1.39","1.4","1.40","1.41","1.42","1.43","1.44","1.44.1","1.45","1.46","1.46.1","1.47","1.5","1.6","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gqhm-4h93-rrhg/GHSA-gqhm-4h93-rrhg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}