PT-2022-26885 · Jenkins · Jenkins Script Security Plugin+1
Daniel Beck
+1
·
Published
2022-10-19
·
Updated
2023-11-22
·
CVE-2022-43401
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Script Security Plugin versions 1183.v774b 0b 0a a 451 and earlier
Description
A sandbox bypass issue involving implicit casts by the Groovy language runtime allows attackers with permission to define and run sandboxed scripts to bypass sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. This affects scripts including Pipelines.
Recommendations
For versions 1183.v774b 0b 0a a 451 and earlier, update to a version that fixes the sandbox bypass vulnerability to prevent attackers from executing arbitrary code in the context of the Jenkins controller JVM.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Script Security Plugin