Sandbox Bypass Vulnerability in Jenkins Pipeline: Groovy Plugin
CVE-2022-43402
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 October 2022
What is CVE-2022-43402?
The vulnerability allows attackers with permission to create and execute sandboxed scripts in Jenkins to circumvent the sandbox protections. This flaw occurs due to implicit type casting in the Groovy language runtime, enabling the execution of arbitrary code within the Jenkins controller JVM. Users of Jenkins Pipeline: Groovy Plugin version 2802.v5ea_628154b_c2 and earlier are particularly affected, emphasizing the need for immediate review and mitigation to safeguard against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Pipeline: Groovy Plugin <= 2802.v5ea_628154b_c2
Jenkins Pipeline: Groovy Plugin 2759.2761.vd6e8d2a_15980
Jenkins Pipeline: Groovy Plugin 2746.2748.v365128b_c26d7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved