Jenkins Pipeline Remote Loader Plugin before 1.5 provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
{
"nvd_published_at": "2019-05-31T15:29:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2022-08-30T18:21:15Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-183",
"CWE-693"
]
}