QID 997334
Date Published: 2024-02-20
QID 997334: Java (Maven) Security Update for org.jenkins-ci.plugins.workflow:workflow-cps (GHSA-mhwq-4mh7-fv7c)
Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mhwq-4mh7-fv7c for updates and patch information.
Vendor References
- GHSA-mhwq-4mh7-fv7c -
github.com/advisories/GHSA-mhwq-4mh7-fv7c
CVEs related to QID 997334
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mhwq-4mh7-fv7c | org.jenkins-ci.plugins.workflow:workflow-cps |
|