QID 997340
Date Published: 2024-02-20
QID 997340: Java (Maven) Security Update for cprice404:pipeline-classpath (GHSA-r5c7-qcc9-5v7m)
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r5c7-qcc9-5v7m for updates and patch information.
Vendor References
- GHSA-r5c7-qcc9-5v7m -
github.com/advisories/GHSA-r5c7-qcc9-5v7m
CVEs related to QID 997340
Software Advisories
| Advisory ID | Software | Component | Link |
|---|