8.8
CVSSv3

CVE-2023-24422

Published: 26/01/2023 Updated: 04/02/2023
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2

Vulnerability Summary

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and previous versions allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

jenkins script security

Vendor Advisories

Description<!---->A flaw was found in the script-security Jenkins Plugin In affected versions of the script-security plugin, property assignments performed implicitly by the Groovy language runtime when invoking map constructors were not intercepted by the sandbox This vulnerability allows attackers with permission to define and run sandboxed scr ...

Github Repositories

CVE-2023-24422 A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM authentication complexity vector not