CVE-2024-34145
published 2024-05-02CVE-2024-34145: A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.00%
59.0th percentile
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | git_server_plugin | — | — |
| jenkins | script_security | <= 1335.vf07d9ce377a_e | — |
| jenkins | script_security_plugin | — | — |
| jenkins | subversion_partial_release_manager_plugin | — | — |
| jenkins | telegram_bot_plugin | — | — |
| jenkins_project | jenkins_script_security_plugin | <= 1335.vf07d9ce377a_e | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes
vendor_redhat·2024-05-02·CVSS 8.8
CVE-2024-34145 [HIGH] CWE-693 jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes
jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
A sandbox bypass vulnerability was found in the Jenkins Script Security Plugin within the sandbox-defined classes, enabling the circumvention of security restrictions. This flaw allows authenticated attackers to define and execute sandboxed scripts, including Pipelines, bypassing sandbox protection mechanisms and executing arbitrary code within
Jenkins
Jenkins Security Advisory 2024-05-02
vendor_jenkins·2024-05-02·CVSS 9.8
CVE-2016-3721 [CRITICAL] Jenkins Security Advisory 2024-05-02
Title: Jenkins Security Advisory 2024-05-02
Jenkins Security Advisory 2024-05-02
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Git server
Plugin
Script Security
Plugin
Subversion Partial Release Manager
Plugin
Telegram Bot
Plugin
Descriptions
Multiple sandbox bypass vulnerabilities in Script Security
GHSA
Jenkins Script Security Plugin sandbox bypass vulnerability
ghsa·2024-05-02
CVE-2024-34145 [HIGH] CWE-290 Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.
Multiple sandbox bypass vulnerabilities exist in Script Security Plugin 1335.vf07d9ce377a_e and earlier:
- Crafted constructor bodies that invoke other constructors can be used to construct any subclassable type via implicit casts.
- Sandbox-defined Groovy classes that shadow specific non-sandbox-defined classes can be used to construct any subclassable type.
These vulnerabilities allow attackers with permission to d
OSV
Jenkins Script Security Plugin sandbox bypass vulnerability
osv·2024-05-02
CVE-2024-34145 [HIGH] Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.
Multiple sandbox bypass vulnerabilities exist in Script Security Plugin 1335.vf07d9ce377a_e and earlier:
- Crafted constructor bodies that invoke other constructors can be used to construct any subclassable type via implicit casts.
- Sandbox-defined Groovy classes that shadow specific non-sandbox-defined classes can be used to construct any subclassable type.
These vulnerabilities allow attackers with permission to d
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-02
Published