Security features bypass in Script Security - CVE-2024-34144

 

Security features bypass in Script Security - CVE-2024-34144

Published: May 6, 2024


Vulnerability identifier: #VU89153
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34144
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the sandbox bypass issue involving crafted constructor bodies. A remote user can define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code on the system.


Affected software

Script Security
OpenShift Developer Tools and Services
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-34144

Install updates from vendor's website.

Script Security - update to 1336.vf33a_a_9863911
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.12.1730119231-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8

External References

Related Security Bulletins