VDB
Sign up
CRITICAL9.9

GHSA-xvxq-hq48-xphm

Sandbox bypass in Script Security Plugin

Quick fix

GHSA-xvxq-hq48-xphm — org.jenkins-ci.plugins:script-security: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.54</version> for org.jenkins-ci.plugins:script-security

Details

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.plugins:script-security
Introduced in: 0Fixed in: 1.54
Fix# pom.xml: bump <version>1.54</version> for org.jenkins-ci.plugins:script-security

References