Sandbox Bypass Vulnerability in Jenkins Script Security Plugin Allows Arbitrary Code Execution
CVE-2024-34145
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 May 2024
What is CVE-2024-34145?
A critical sandbox bypass vulnerability exists in the Jenkins Script Security Plugin that affects versions up to 1335.vf07d9ce377a_e. This vulnerability allows attackers with permissions to define and execute sandboxed scripts—such as Pipelines—to bypass the security measures in place. By exploiting this flaw, attackers can run arbitrary code within the context of the Jenkins controller JVM, thereby compromising the integrity of the Jenkins environment. It is crucial for users of affected versions to apply necessary updates and patches to mitigate risks.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1335.vf07d9ce377a_e