QID 996430
Date Published: 2023-12-26
QID 996430: Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-hvmx-5hv4-f235)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hvmx-5hv4-f235 for updates and patch information.
Vendor References
- GHSA-hvmx-5hv4-f235 -
github.com/advisories/GHSA-hvmx-5hv4-f235
CVEs related to QID 996430
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hvmx-5hv4-f235 | org.jenkins-ci.plugins:script-security |
|