CVE-2022-43406

Source
https://cve.org/CVERecord?id=CVE-2022-43406
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43406.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-43406
Aliases
Downstream
Published
2022-10-19T16:15:10.427Z
Modified
2026-03-11T00:29:38.670179Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "583.vf3b_454e43966"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43406.json"