Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43401


A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.


Published

2022-10-19T16:15:10.127

Last Modified

2024-11-21T07:26:24.483

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins script_security ≤ 1183.v774b_0b_0a_a_451 Yes

References