PT-2022-26888 · Jenkins · Jenkins Script Security Plugin+1

Daniel Beck

+1

·

Published

2022-10-19

·

Updated

2023-11-22

·

CVE-2022-43404

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Script Security Plugin versions 1183.v774b 0b 0a a 451 and earlier
Description A sandbox bypass issue exists, involving crafted constructor bodies and calls to sandbox-generated synthetic constructors, which allows attackers with permission to define and run sandboxed scripts to bypass sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Recommendations For versions 1183.v774b 0b 0a a 451 and earlier, update to a version that contains a fix for this issue to prevent sandbox bypass and arbitrary code execution.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2022-43404
GHSA-27RF-8MJP-R363
RHSA-2023:0560
RHSA-2023:0777
RHSA-2023:1064
RHSA-2023:3198

Affected Products

Jenkins
Jenkins Script Security Plugin