Protection Mechanism Failure in Script Security - CVE-2022-43403

 

Protection Mechanism Failure in Script Security - CVE-2022-43403

Published: October 24, 2022


Vulnerability identifier: #VU68597
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-43403
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A remote user can bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.


Affected software

Script Security
Red Hat OpenShift Container Platform
Oracle Communications Cloud Native Core Unified Data Repository
cri-o (Red Hat package)
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2022-43403

Install updates from vendor's website.

Script Security - update to 1184.v85d16b_d851b_3
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.51
cri-o (Red Hat package) - addressed in versions 1.23.5-5.rhaos4.10.gitd9dec98.el7, 1.23.5-5.rhaos4.10.gitd9dec98.el8
jenkins (Red Hat package) - addressed in versions 2.361.1.1675668150-1.el8, 2.361.4.1675702346-3.el8, 2.387.1.1683009763-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1675702407-1.el8

External References

Related Security Bulletins