CVE-2022-43403
Jenkins Script Security Plugin sandbox bypass vulnerability
9.9
CRITICAL
CVSS 3.1
EPSS 1.4%
描述
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. Script Security Plugin 1184.v85d16b_d851b_3 intercepts per-element casts when casting array-like values to array types.
如何修補 CVE-2022-43403
要修補 CVE-2022-43403,請將受影響套件升級到下列已修補版本。
- —升級至 1184.v85d16b_d851b_3 或更新版本
CVE-2022-43403 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1184.v85d16b_d851b_3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |