QID 996416
Date Published: 2023-12-26
QID 996416: Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-76q7-r3g4-wvm4)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-76q7-r3g4-wvm4 for updates and patch information.
Vendor References
- GHSA-76q7-r3g4-wvm4 -
github.com/advisories/GHSA-76q7-r3g4-wvm4
CVEs related to QID 996416
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-76q7-r3g4-wvm4 | org.jenkins-ci.plugins:script-security |
|