High severity8.8NVD Advisory· Published Dec 10, 2018· Updated Jun 17, 2026
CVE-2018-1000866
CVE-2018-1000866
Description
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-cpsMaven | < 2.60 | 2.60 |
org.jenkins-ci.plugins:script-securityMaven | < 1.48 | 1.48 |
Affected products
4- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- ghsa-coords2 versionspkg:maven/org.jenkins-ci.plugins.workflow/workflow-cpspkg:maven/org.jenkins-ci.plugins/script-security
< 2.60+ 1 more
- (no CPE)range: < 2.60
- (no CPE)range: < 1.48
Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHBA-2019:0326nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHBA-2019:0327nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-gqhm-4h93-rrhgghsaADVISORY
- jenkins.io/security/advisory/2018-10-29/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000866ghsaADVISORY
- github.com/jenkinsci/script-security-plugin/commit/16c862ae9d4038a3edbd8bdfb0fd1401a509d56bghsaWEB
- github.com/jenkinsci/workflow-cps-plugin/commit/0eb89aaf24065dbbdf6db84516ac1a52cd435e6dghsaWEB
- github.com/jenkinsci/workflow-cps-plugin/commit/e1c56eb6d85d513cb24dfe188e6f592d0ff84b38ghsaWEB
News mentions
0No linked articles in our index yet.