CVE-2020-2135: Jenkins Script Security

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

Affected products

  • Jenkins Script Security: up to and including 1.70

Published 2020-03-09. Last modified 2026-06-17.