Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-43406
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-43406

2022-10-1900:00:00
jenkins
www.cve.org
4
jenkins
pipeline
sandbox bypass

9.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.2%

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CNA Affected

[
  {
    "product": "Jenkins Pipeline: Deprecated Groovy Libraries Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "583.vf3b_454e43966",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

9.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.2%