Description
A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2824%20%282%29
Related Vulnerabilities
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2023-34617 Vulnerability in maven package com.owlike:genson
CVE-2022-37724 Vulnerability in maven package wonder.utilities:utilities
CVE-2018-1000665 Vulnerability in maven package org.apache.geronimo.plugins:dojo
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-pmml-examples