Security features bypass in Script Security - CVE-2024-34144
Published: May 6, 2024
Vulnerability identifier: #VU89153
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34144
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the sandbox bypass issue involving crafted constructor bodies. A remote user can define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code on the system.
Affected software
Script Security
OpenShift Developer Tools and Services
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
OpenShift Developer Tools and Services
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2024-34144
Install updates from vendor's website.
Script Security - update to 1336.vf33a_a_9863911
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.12.1730119231-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.12.1730119231-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins Script Security plugin
- Red Hat Product OCP Tools 4.14. Red Hat Product Security has rated this update as having a security impact of Important update for Openshift Jenkins
- Red Hat Product OCP Tools 4.12. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Product OCP Tools 4.13. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins