DescriptionDhananjay Arunesh
2020-03-31 08:02:25 UTC
A vulnerability was found in Jenkins Script Security Plugin 1.69 and earlier, where sandbox protection could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
Reference:
http://www.openwall.com/lists/oss-security/2020/02/12/3
Comment 1Dhananjay Arunesh
2020-03-31 08:03:02 UTC
Created jenkins-script-security-plugin tracking bugs for this issue:
Affects: fedora-30 [bug 1819094]