QID 996954
Date Published: 2024-02-05
QID 996954: Java (Maven) Security Update for org.jenkins-ci.plugins.workflow:workflow-cps (GHSA-gqhm-4h93-rrhg)
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gqhm-4h93-rrhg for updates and patch information.
Vendor References
- GHSA-gqhm-4h93-rrhg -
github.com/advisories/GHSA-gqhm-4h93-rrhg
CVEs related to QID 996954
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gqhm-4h93-rrhg | org.jenkins-ci.plugins.workflow:workflow-cps |
|