CVE-2024-34144: Critical severity maven/org.jenkins-ci.plugins:script-security vulnerability

Published May 2, 2024
·
Updated

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377ae and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Other sources

Jenkins Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.

Multiple sandbox bypass vulnerabilities exist in Script Security Plugin 1335.vf07d9ce377ae and earlier:

- Crafted constructor bodies that invoke other constructors can be used to construct any subclassable type via implicit casts.

- Sandbox-defined Groovy classes that shadow specific non-sandbox-defined classes can be used to construct any subclassable type.

These vulnerabilities allow attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

- These issues are caused by an incomplete fix of SECURITY-2824).

Script Security Plugin 1336.vf33aa9863911 has additional restrictions and sanity checks to ensure that super constructors cannot be constructed without being intercepted by the sandbox:

- Calls to to other constructors using this are now intercepted by the sandbox.

- Classes in packages that can be shadowed by Groovy-defined classes are no longer ignored by the sandbox when intercepting super constructor calls.

GitHub

Affected Software

3 affected componentsFixes available
maven/org.jenkins-ci.plugins:script-security<1336.vf33a
1336.vf33a
redhat/Script Security Plugin<1336.
1336.
Jenkins Script Security Jenkins<=1335.vf07d9ce377a_e

Event History

May 2, 2024
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Advisory Published
via GitHub·03:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-34144?

CVE-2024-34144 is a high severity vulnerability that allows sandbox bypass in Jenkins Script Security Plugin.

2

How do I fix CVE-2024-34144?

To fix CVE-2024-34144, update Jenkins Script Security Plugin to version 1336.vf33a or later.

3

What type of vulnerability is CVE-2024-34144?

CVE-2024-34144 is a sandbox bypass vulnerability that allows execution of arbitrary code.

4

Who is affected by CVE-2024-34144?

Users of Jenkins Script Security Plugin version 1335.vf07d9ce377a_e and earlier are affected by CVE-2024-34144.

5

What can attackers do exploiting CVE-2024-34144?

Attackers exploiting CVE-2024-34144 can execute arbitrary code in the context of the Jenkins environment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203