CVE-2020-2279
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.
- Affected products
- Email Extension Plugin, Jenkins, Jenkins Script Security Plugin, Warnings Next Generation Plugin, Warnings Plugin
- Jenkins Script Security
- ≤ 1.74
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2020-09-23
CVE-2020-2279 at NVD
No indexed exploits for CVE-2020-2279 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-2279 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.