CVE-2022-43404: Critical severity Jenkins Script Security Jenkins vulnerability
A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b0b0aa451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Other sources
A sandbox bypass vulnerability was found in several Jenkins plugins. This could allow an authenticated attacker to execute arbitrary code within the Jenkins JVM controller. Exploitation could be achieved by crafting untrusted libraries or pipelines, compromising the integrity, availability, and confidentiality of Jenkins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.11.1683009941-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.12.1675702407-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.10.1675144701-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.9.1675668922-1.el8 - Upgrade
Upgrade
redhat/Script Security Pluginto a version that resolves this vulnerability.Fixed in 1184.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-43404?
CVE-2022-43404 is classified as a high-severity vulnerability due to its potential to allow attackers to bypass security controls.
How do I fix CVE-2022-43404?
To fix CVE-2022-43404, update the Jenkins Script Security Plugin to version 1184 or later.
What versions of Jenkins are affected by CVE-2022-43404?
CVE-2022-43404 affects Jenkins Script Security Plugin versions up to and including 1183.v774b_0b_0a_a_451.
Who is impacted by CVE-2022-43404?
Users of Jenkins who have the Script Security Plugin installed and allow sandboxed scripts are vulnerable to CVE-2022-43404.
What type of attack is possible with CVE-2022-43404?
CVE-2022-43404 allows an attacker to bypass sandbox restrictions and execute unauthorized commands in Jenkins.