Sandbox Bypass Vulnerability in Jenkins Pipeline: Groovy Libraries Plugin
CVE-2022-43405

9.9CRITICAL

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
19 October 2022

Summary

A vulnerability exists in the Jenkins Pipeline: Groovy Libraries Plugin that allows attackers, with the necessary permissions, to evade sandbox restrictions. By exploiting this flaw, they can define untrusted Pipeline libraries and execute sandboxed scripts, potentially leading to arbitrary code execution within the Jenkins controller JVM. This presents a significant risk as it undermines the security model of the Jenkins platform, allowing malicious actors to manipulate functionalities and access sensitive data.

Affected Version(s)

Jenkins Pipeline: Groovy Libraries Plugin <= 612.v84da_9c54906d

Jenkins Pipeline: Groovy Libraries Plugin 593.595.vfc6485d13dcd

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.