Description

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

INFO

Published Date :

2024-05-02T13:28:03.965Z

Last Modified :

2025-02-13T17:52:25.384Z

Source :

jenkins
AFFECTED PRODUCTS

The following products are affected by CVE-2024-34145 vulnerability.

Vendors Products
Jenkins
  • Script Security
Redhat
  • Ocp Tools

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact