CVE-2023-24422: OS Command Injection

Published Jan 24, 2023
·
Updated

A flaw was found in the script-security Jenkins Plugin. In affected versions of the script-security plugin, property assignments performed implicitly by the Groovy language runtime when invoking map constructors were not intercepted by the sandbox. This vulnerability allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Other sources

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a2fb25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Script Security Plugin provides a sandbox feature that allows low-privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed. In Script Security Plugin 1228.vd93135a2fb25 and earlier, property assignments performed implicitly by the Groovy language runtime when invoking map constructors were not intercepted by the sandbox. This vulnerability allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-3016

Red Hat

Affected Software

8 affected componentsFixes available
redhat/jenkins<2-plugins-0:4.11.1683009941-1.el8
2-plugins-0:4.11.1683009941-1.el8
redhat/jenkins<2-plugins-0:4.12.1683009955-1.el8
2-plugins-0:4.12.1683009955-1.el8
redhat/jenkins<2-plugins-0:4.12.1686649756-1.el8
2-plugins-0:4.12.1686649756-1.el8
redhat/jenkins<2-plugins-0:4.13.1684911916-1.el8
2-plugins-0:4.13.1684911916-1.el8
redhat/jenkins<2-plugins-0:4.10.1680703106-1.el8
2-plugins-0:4.10.1680703106-1.el8
maven/org.jenkins-ci.plugins:script-security<1229.v4880b
1229.v4880b
redhat/Script Security Plugin<1229.
1229.
Jenkins Script Security Jenkins<1229.v4880b_b_e905a_6

Event History

Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 26, 2023
Advisory Published
09:30 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-24422?

CVE-2023-24422 is classified as a high severity vulnerability due to its potential to allow attacker exploitation.

2

How do I fix CVE-2023-24422?

To fix CVE-2023-24422, upgrade the Jenkins Script Security Plugin to version 1229.v4880b or later.

3

Which versions of Jenkins are affected by CVE-2023-24422?

CVE-2023-24422 affects multiple versions of the Jenkins Script Security Plugin prior to 1229.v4880b.

4

What type of vulnerability is CVE-2023-24422?

CVE-2023-24422 is a script execution vulnerability that involves improper sandboxing in the Groovy language runtime.

5

Who is impacted by CVE-2023-24422?

Individuals or organizations that use the affected versions of the Jenkins Script Security Plugin may be impacted by CVE-2023-24422.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203