« Volver al listado

CVE-2022-43406

Estado: ModificadaCrítica (9.9)—

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-43406",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins project",
          "product": "Jenkins Pipeline: Deprecated Groovy Libraries Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "583.vf3b_454e43966"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-19T16:15:10.427",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2022/10/19/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2824%20%282%29",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2022/10/19/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2824%20%282%29",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de omisión del sandbox en Jenkins Pipeline: Deprecated Groovy Libraries Plugin versiones 583.vf3b_454e43966 y anteriores, permite a atacantes con permiso para definir bibliotecas de Pipeline que no son confiables y para definir y ejecutar scripts con sandbox, incluyendo Pipelines, omitir la protección del sandbox y ejecutar código arbitrario en el contexto de la JVM del controlador de Jenkins"
    }
  ],
  "lastModified": "2026-06-17T05:06:27.093",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:groovy_libraries:*:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0C6B815-CBD3-4878-AE2F-70A6330D695F",
              "versionEndIncluding": "583.vf3b_454e43966"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}