CVE-2023-24422
Sandbox bypass in Jenkins Script Security Plugin
8.8
HIGH
CVSS 3.1
EPSS 0.58%
描述
A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
如何修補 CVE-2023-24422
要修補 CVE-2023-24422,請將受影響套件升級到下列已修補版本。
- —升級至 1229.v4880b 或更新版本
CVE-2023-24422 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1229.v4880b
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |