[MAVEN:GHSA-76QJ-9GWH-PVV3] Sandbox bypass in Jenkins Script Security Plugin

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/script-security < 1229.v4880b
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/script-security = 1229.v4880b
ID
MAVEN:GHSA-76QJ-9GWH-PVV3
Severity
high
URL
https://github.com/advisories/GHSA-76qj-9gwh-pvv3
Published
2023-01-26T21:30:19
(20 months ago)
Modified
2024-01-04T12:18:05
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/script-security org.jenkins-ci.plugins script-security < 1229.v4880b
Fixed pkg:maven/org.jenkins-ci.plugins/script-security org.jenkins-ci.plugins script-security = 1229.v4880b
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...