CVE-2022-1183
published 2022-05-19CVE-2022-1183: On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.45%
93.0th percentile
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.3-1 (bookworm) | bind9 1:9.18.3-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | 9.18.0 – 9.18.2 | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.18.3-1 | 1:9.18.3-1 |
| isc | bind9 | >= 0 < 1:9.18.3-1 | 1:9.18.3-1 |
| isc | bind9 | >= 0 < 1:9.18.3-1 | 1:9.18.3-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa9.9CRITICAL
osv7.5HIGH
vendor_redhat9.9CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
vendor_redhat·2022-10-19·CVSS 9.9
CVE-2022-43404 [CRITICAL] CWE-693 jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
A sandbox bypass vulnerability was found in several Jenkins plugins. This could allow an authenticated attacker to execute arbitrary code within the Jenkins JVM controller. Exploitation could be achieved by crafting untrusted libraries or pipelines, compromising the integrity, availability, and confidentiality o
Red Hat
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
vendor_redhat·2022-10-19·CVSS 9.9
CVE-2022-43403 [CRITICAL] CWE-693 jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
A sandbox bypass vulnerability was found in several Jenkins plugins. This could allow an authenticated attacker to execute arbitrary code within the Jenkins JVM controller. Exploitation could be achieved by crafting untrusted libraries or pipelines, compromising the integrity, availability, and confidentiality of Jenkins.
Package: jenkins-2-plugi
Red Hat
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
vendor_redhat·2022-10-19·CVSS 9.9
CVE-2022-43401 [CRITICAL] CWE-693 jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin
A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
A sandbox bypass vulnerability was found in several Jenkins plugins. This could allow an authenticated attacker to execute arbitrary code within the Jenkins JVM controller. Exploitation could be achieved by crafting untrusted libraries or pipelines, compromising the integrity, availability, and confidentiality of Jenkins.
Pac
Red Hat
bind: Destroying a TLS session early causes assertion failure
vendor_redhat·2022-05-18·CVSS 7.5
CVE-2022-1183 [HIGH] CWE-617 bind: Destroying a TLS session early causes assertion failure
bind: Destroying a TLS session early causes assertion failure
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
A flaw was found in BIND due to a reachable assertion triggered if a TLS connection to a configured HTTP TLS listener with a defined endpoint is destroyed too early. This flaw allows a remote attacker to trigger a denial of service condition on the targeted system.
Statement: This flaw only affects
Ubuntu
Bind vulnerability
vendor_ubuntu·2022-05-18
CVE-2022-1183 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Thomas Amgarten discovered that Bind incorrectly handled certain TLS
connections being destroyed. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-1183: bind9 - On vulnerable configurations, the named daemon may, in some circumstances, termi...
vendor_debian·2022·CVSS 7.5
CVE-2022-1183 [HIGH] CVE-2022-1183: bind9 - On vulnerable configurations, the named daemon may, in some circumstances, termi...
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
Scope: local
bookworm: resolved (fixed in 1:9.18.3-1)
bullseye: resolved
forky: resolved (fixed in 1:9.18.3-1)
sid: resolved (fixed in 1:9.18.3-1)
trixie: resolved (fixed in 1:9.18.3-1)
GHSA
Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
ghsa·2022-10-19·CVSS 9.9
CVE-2022-43404 [CRITICAL] CWE-693 Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.
Multiple sandbox bypass vulnerabilities exist in Script Security Plugin and Pipeline: Groovy Plugin:
- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier and in Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier, various casts performed implicitly by the Groovy language runtime were not intercepted by the sandbox. This includes casts performed when returning values from metho
GHSA
Jenkins Script Security Plugin sandbox bypass vulnerability
ghsa·2022-10-19
CVE-2022-43403 [CRITICAL] CWE-693 Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin sandbox bypass vulnerability
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. Script Security Plugin 1184.v85d16b_d851b_3 intercepts per-element casts when casting array-like values to array types.
GHSA
Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
ghsa·2022-10-19·CVSS 9.9
CVE-2022-43401 [CRITICAL] CWE-693 Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.
Multiple sandbox bypass vulnerabilities exist in Script Security Plugin and Pipeline: Groovy Plugin:
- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier and in Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier, various casts performed implicitly by the Groovy language runtime were not intercepted by the sandbox. This includes casts performed when returning values from metho
GHSA
GHSA-wgcp-6p65-qv57: On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure
ghsa_unreviewed·2022-05-20
CVE-2022-1183 [HIGH] CWE-617 GHSA-wgcp-6p65-qv57: On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
OSV
CVE-2022-1183: On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure
osv·2022-05-19·CVSS 7.5
CVE-2022-1183 [HIGH] CVE-2022-1183: On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-19
Published