QID 996904
Date Published: 2024-01-30
QID 996904: Java (Maven) Security Update for org.jenkinsci.plugins:pipeline-model-definition (GHSA-x6jx-cxg3-mggh)
Jenkins Script Security sandbox protection could be circumvented during the script compilation phase by applying AST transforming annotations such as @Grab to source code elements.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x6jx-cxg3-mggh for updates and patch information.
Vendor References
- GHSA-x6jx-cxg3-mggh -
github.com/advisories/GHSA-x6jx-cxg3-mggh
CVEs related to QID 996904
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x6jx-cxg3-mggh | org.jenkinsci.plugins:pipeline-model-definition |
|