QID 996418
Date Published: 2023-12-26
QID 996418: Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-9fp8-64xf-w957)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9fp8-64xf-w957 for updates and patch information.
Vendor References
- GHSA-9fp8-64xf-w957 -
github.com/advisories/GHSA-9fp8-64xf-w957
CVEs related to QID 996418
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9fp8-64xf-w957 | org.jenkins-ci.plugins:script-security |
|