Jenkins.Pipeline.Groovy.Plugin.Sandbox.Bypass
Description
This indicates an attack attempt to exploit a Sandbox Bypass vulnerability in Jenkins Pipeline Groovy plugin.
This vulnerability is due to objects being created outside the sandbox, which can lead to code execution beyond its boundaries. A remote attacker, with the capability to configure and execute a pipeline, might exploit this to achieve remote code execution.
Affected Products
Jenkins Pipeline: Groovy Plugin 2.63 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Refer to the vendor's advisory for updates:
https://www.jenkins.io/security/advisory/2019-03-06/
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |