Vulnerabilities > CVE-2019-16538 - Incorrect Authorization vulnerability in Jenkins Script Security

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
jenkins
CWE-863

Summary

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.

Vulnerable Configurations

Part Description Count
Application
Jenkins
96

Common Weakness Enumeration (CWE)