Логотип exploitDog
bind:CVE-2022-43402
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43402

Количество 3

Количество 3

redhat логотип

CVE-2022-43402

больше 3 лет назад

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2022-43402

больше 3 лет назад

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-mqc2-w9r8-mmxm

больше 3 лет назад

Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-43402

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS3: 9.9
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-43402

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS3: 9.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqc2-w9r8-mmxm

Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution

CVSS3: 9.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу