Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35183
HistoryApr 21, 2022 - 12:43 a.m.

Sandbox Bypass

2022-04-2100:43:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33
jenkins
pipeline
sandbox bypass
vulnerability
shared groovy libraries
arbitrary code execution
item/configure permission
caching

EPSS

0.001

Percentile

42.8%

Jenkins Pipeline is vulnerable to sandbox bypass. It uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists. A flaw was found in Jenkins. The Pipeline: Shared Groovy Libraries plugin uses the names of Pipeline libraries to create cache directories without any sanitization. This flaw allows attackers with item/configure permission to execute arbitrary code in the context of the Jenkins controller JVM, using specially crafted library names if a global Pipeline library configured to use caching already exists.

EPSS

0.001

Percentile

42.8%