High severity8.8NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026
CVE-2020-2110
CVE-2020-2110
Description
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:script-securityMaven | < 1.70 | 1.70 |
Affected products
3cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*range: <=1.69
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/02/12/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-qvmf-36h5-3f5vghsaADVISORY
- jenkins.io/security/advisory/2020-02-12/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-2110ghsaADVISORY
- github.com/jenkinsci/script-security-plugin/commit/1a09bdcf789b87c4e158aacebd40937c64398de3ghsaWEB
News mentions
1- Jenkins Security Advisory 2020-02-12Jenkins Security Advisories · Feb 12, 2020