Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-43405

Опубликовано: 19 окт. 2022
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:groovy_libraries:*:*:*:*:*:jenkins:*:*
Версия до 612.v84da_9c54906d (включая)

EPSS

Процентиль: 37%
0.00157
Низкий

9.9 Critical

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.9
redhat
больше 3 лет назад

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS3: 8.8
github
больше 3 лет назад

Sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin and Pipeline: Deprecated Groovy Libraries Plugin

EPSS

Процентиль: 37%
0.00157
Низкий

9.9 Critical

CVSS3

Дефекты

NVD-CWE-noinfo