CVE-2022-43405: Critical severity Jenkins Groovy Libraries Jenkins vulnerability
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Other sources
A sandbox bypass vulnerability was found in several Jenkins plugins. This could allow an authenticated attacker to execute arbitrary code within the Jenkins JVM controller. Exploitation could be achieved by crafting untrusted libraries or pipelines, compromising the integrity, availability, and confidentiality of Jenkins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.11.1683009941-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.12.1675702407-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.10.1675144701-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.9.1675668922-1.el8 - Upgrade
Upgrade
redhat/Pipeline Groovy Libraries Pluginto a version that resolves this vulnerability.Fixed in 613. - Upgrade
Upgrade
redhat/Pipeline Groovy Libraries Pluginto a version that resolves this vulnerability.Fixed in 612.614.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-43405?
CVE-2022-43405 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2022-43405?
To remediate CVE-2022-43405, update Jenkins Pipeline: Groovy Libraries Plugin to version 612.v84da_9c54906d or later.
What are the affected versions for CVE-2022-43405?
CVE-2022-43405 affects Jenkins Pipeline: Groovy Libraries Plugin versions up to and including 612.v84da_9c54906d.
Can CVE-2022-43405 be exploited remotely?
Yes, attackers with the required permissions can exploit CVE-2022-43405 remotely by defining untrusted Pipeline libraries.
What actions can be taken to mitigate CVE-2022-43405?
To mitigate CVE-2022-43405, ensure that only trusted users have permission to define untrusted Pipeline libraries in Jenkins.