Sandbox bypass in Jenkins Script Security Plugin
High severity
GitHub Reviewed
Published
Jan 26, 2023
to the GitHub Advisory Database
•
Updated Jan 4, 2024
Package
Affected versions
< 1229.v4880b
Patched versions
1229.v4880b
Description
Published by the National Vulnerability Database
Jan 26, 2023
Published to the GitHub Advisory Database
Jan 26, 2023
Reviewed
Jan 27, 2023
Last updated
Jan 4, 2024
A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
References