Users with the ability to configure sandboxed Groovy and Pipeline scripts, including those from SCM, are able to use a type coercion feature in Groovy to create new File objects from strings. This allowed reading arbitrary files on the Jenkins master file system.
Affected versions: Script Security Plugin up to and including 1.36
External References:
https://jenkins.io/security/advisory/2017-12-11/
Statement:
This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat Enterprise OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.