Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43403


A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.


Published

2022-10-19T16:15:10.253

Last Modified

2024-11-21T07:26:24.753

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins script_security ≤ 1183.v774b_0b_0a_a_451 Yes

References