First published: Wed Oct 19 2022(Updated: )
A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2-plugins-0:4.11.1683009941-1.el8 | 2-plugins-0:4.11.1683009941-1.el8 |
redhat/jenkins | <2-plugins-0:4.12.1675702407-1.el8 | 2-plugins-0:4.12.1675702407-1.el8 |
redhat/jenkins | <2-plugins-0:4.10.1675144701-1.el8 | 2-plugins-0:4.10.1675144701-1.el8 |
redhat/jenkins | <2-plugins-0:4.9.1675668922-1.el8 | 2-plugins-0:4.9.1675668922-1.el8 |
Jenkins Pipeline\ | <=2802.v5ea_628154b_c2 | |
maven/org.jenkins-ci.plugins.workflow:workflow-cps | <2803.v1a | 2803.v1a_f77ffcc773 |
redhat/Pipeline Groovy Plugin | <2803. | 2803. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-43402 has been categorized as a critical vulnerability allowing sandbox bypass in Jenkins.
To mitigate CVE-2022-43402, upgrade to Jenkins Pipeline: Groovy Plugin version 2803.v1a_f77ffcc773 or later.
CVE-2022-43402 affects Jenkins users who utilize the Groovy language runtime in sandboxed scripts, specifically in versions prior to 2803.
Attackers with permission to define and run sandboxed scripts in Jenkins are able to exploit CVE-2022-43402.
The main issue with CVE-2022-43402 is that it allows attackers to bypass sandbox protection, compromising script security in Jenkins.