[MAVEN:GHSA-R6MC-MRVR-23CR] Sandbox bypass in Jenkins Pipeline: Groovy Plugin

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

ID
MAVEN:GHSA-R6MC-MRVR-23CR
Severity
critical
URL
https://github.com/advisories/GHSA-r6mc-mrvr-23cr
Published
2022-05-13T01:14:26
(2 years ago)
Modified
2023-10-25T19:45:01
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins.workflow/workflow-cps org.jenkins-ci.plugins.workflow workflow-cps < 2.64
Fixed pkg:maven/org.jenkins-ci.plugins.workflow/workflow-cps org.jenkins-ci.plugins.workflow workflow-cps = 2.64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...