Jenkins Script Security 1189.vb a b7c8fd5fde for Jenkins

CPE Details

Jenkins Script Security 1189.vb a b7c8fd5fde for Jenkins
1189.vb_a_b_7c8fd5fde
2022-11-23
01h21 +00:00
2022-11-23
01h23 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:jenkins:script_security:1189.vb_a_b_7c8fd5fde:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

script_security

Version

1189.vb_a_b_7c8fd5fde

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-24422 2023-01-24 00h00 +00:00 A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
8.8
Haute
CVE-2022-45379 2022-11-14 23h00 +00:00 Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
7.5
Haute