PT-2022-26885 · Jenkins · Jenkins Script Security Plugin+1

Daniel Beck

+1

·

Published

2022-10-19

·

Updated

2023-11-22

·

CVE-2022-43401

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Script Security Plugin versions 1183.v774b 0b 0a a 451 and earlier
Description A sandbox bypass issue involving implicit casts by the Groovy language runtime allows attackers with permission to define and run sandboxed scripts to bypass sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. This affects scripts including Pipelines.
Recommendations For versions 1183.v774b 0b 0a a 451 and earlier, update to a version that fixes the sandbox bypass vulnerability to prevent attackers from executing arbitrary code in the context of the Jenkins controller JVM. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2022-43401
GHSA-7VR5-72W7-Q6JC
RHSA-2023:0560
RHSA-2023:0777
RHSA-2023:1064
RHSA-2023:3198

Affected Products

Jenkins
Jenkins Script Security Plugin