Protection Mechanism Failure Affecting org.jenkins-ci.plugins:script-security package, versions [,1184.v85d16b_d851b_3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-3057193
  • published20 Oct 2022
  • disclosed19 Oct 2022
  • creditDevin Nusbaum

Introduced: 19 Oct 2022

CVE-2022-43403  (opens in a new tab)
CWE-693  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:script-security to version 1184.v85d16b_d851b_3 or higher.

Overview

org.jenkins-ci.plugins:script-security is a package that allows Jenkins administrators to control what in-process scripts can be run by less-privileged users.

Affected versions of this package are vulnerable to Protection Mechanism Failure when casting an array-like value to an array type, per-element casts to the component type of the array are not intercepted by the sandbox. Exploiting this vulnerability allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS Scores

version 3.1