Description

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

INFO

Published Date :

2024-05-02T13:28:03.226Z

Last Modified :

2025-02-13T17:52:24.865Z

Source :

jenkins
AFFECTED PRODUCTS

The following products are affected by CVE-2024-34144 vulnerability.

Vendors Products
Jenkins
  • Script Security
Redhat
  • Ocp Tools

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact