Security features bypass in Script Security - CVE-2024-34145

 

Security features bypass in Script Security - CVE-2024-34145

Published: May 6, 2024


Vulnerability identifier: #VU89154
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34145
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the sandbox bypass issue involving sandbox-defined classes that shadow specific non-sandbox-defined classes. A remote user can define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code on the system.


Affected software

Script Security
OpenShift Developer Tools and Services
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-34145

Install updates from vendor's website.

Script Security - update to 1336.vf33a_a_9863911
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8

External References

Related Security Bulletins