Sandbox Bypass Vulnerability in Jenkins Pipeline: Groovy Libraries Plugin
CVE-2022-43405
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 October 2022
What is CVE-2022-43405?
A vulnerability exists in the Jenkins Pipeline: Groovy Libraries Plugin that allows attackers, with the necessary permissions, to evade sandbox restrictions. By exploiting this flaw, they can define untrusted Pipeline libraries and execute sandboxed scripts, potentially leading to arbitrary code execution within the Jenkins controller JVM. This presents a significant risk as it undermines the security model of the Jenkins platform, allowing malicious actors to manipulate functionalities and access sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Pipeline: Groovy Libraries Plugin <= 612.v84da_9c54906d
Jenkins Pipeline: Groovy Libraries Plugin 593.595.vfc6485d13dcd
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved