Description
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.
Remediation
References
http://www.securityfocus.com/bid/96981
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2020-6463 Vulnerability in npm package electron
CVE-2020-1925 Vulnerability in maven package org.apache.olingo:odata-client-core
CVE-2021-34078 Vulnerability in npm package lifion-verify-deps
CVE-2019-10445 Vulnerability in maven package org.jenkins-ci.plugins:google-kubernetes-engine
CVE-2017-1000427 Vulnerability in maven package org.webjars.bower:marked