CVE-2022-43402
CVE-2022-43402
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Oct 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Affected products
Jenkins project · Jenkins Pipeline: Groovy PluginWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →