cbcvebase.
CVE-2022-43403
published 2022-10-19

CVE-2022-43403: A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier…

PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
1.43%
70.1th percentile
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsbmc_ami_devx_code_debug_code_coverage_plugin
jenkinsbmc_ami_devx_total_test_plugin
jenkinsbmc_ami_strobe_measurement_task_plugin
jenkinscode_pipeline_plugin
jenkinscompuware_topaz_utilities_plugin
jenkinscontrast_continuous_application_security_plugin
jenkinscredentials_plugin
jenkinscustom_checkbox_parameter_plugin
jenkinscve-2022-43401_in_script_security_plugin
jenkinsdeclarative_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsfireline_plugin
jenkinsgeneric_webhook_trigger_plugin
jenkinsgitlab_plugin
jenkinsgroovy_libraries_plugin
jenkinsgroovy_plugin
jenkinsinput_step_plugin
jenkinsjob_import_plugin
jenkinsjob_plugin
jenkinskatalon_plugin
jenkinsmercurial_plugin
jenkinsnunit_plugin
jenkinsrepo_plugin
jenkinss3_explorer_plugin
jenkinsscreenrecorder_plugin

Detection & IOCsextracted from sources · hover to see the quote

  • Attackers must have permission to define and run sandboxed scripts (including Pipelines) to exploit this vulnerability — monitor for unexpected or unauthorized Pipeline/script definitions by low-privileged users in Jenkins
  • Exploitation vector involves casting an array-like value to an array type within a sandboxed Groovy script — inspect sandboxed script content for suspicious array cast expressions as a detection signal
  • Exploitation can be achieved by crafting untrusted libraries or pipelines — audit Jenkins shared libraries and Jenkinsfile sources for untrusted or externally-sourced content
  • ·Vulnerable version is Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier — confirm installed plugin version to assess exposure
  • ·Red Hat notes the affected package (jenkins-2-plugins) in OpenShift Container Platform 3.11 is out of support scope — environments running OCP 3.11 may not receive a vendor patch
  • ·Oracle rates this CVE at CVSS 9.9 in the context of Oracle Communications (Signaling/Jenkins Script component) — Oracle Communications deployments should treat this as critical priority

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
ghsa9.9CRITICAL
osv9.9CRITICAL
vendor_oracle9.9CRITICAL
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.