QID 996957
Date Published: 2024-01-30
QID 996957: Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-jgpm-2862-q5m8)
The previously implemented script security sandbox protections prohibiting the use of unsafe AST transforming annotations such as @Grab (2019-01-08 fix for SECURITY-1266) could be circumvented through use of various Groovy language features:
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jgpm-2862-q5m8 for updates and patch information.
Vendor References
- GHSA-jgpm-2862-q5m8 -
github.com/advisories/GHSA-jgpm-2862-q5m8
CVEs related to QID 996957
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jgpm-2862-q5m8 | org.jenkins-ci.plugins:script-security |
|