QID 996409
Date Published: 2023-12-26
QID 996409: Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-m26f-w3h5-62fj)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions in increment and decrement expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m26f-w3h5-62fj for updates and patch information.
Vendor References
- GHSA-m26f-w3h5-62fj -
github.com/advisories/GHSA-m26f-w3h5-62fj
CVEs related to QID 996409
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m26f-w3h5-62fj | org.jenkins-ci.plugins:script-security |
|