Critical severity9.9NVD Advisory· Published Oct 19, 2022· Updated Jun 17, 2026
CVE-2022-43403
CVE-2022-43403
Description
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:script-securityMaven | < 1184.v85d16b_d851b_3 | 1184.v85d16b_d851b_3 |
Affected products
3cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*range: <=1183.v774b_0b_0a_a_451
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2022/10/19/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-f6mq-6fx5-w2chghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-43403ghsaADVISORY
- www.jenkins.io/security/advisory/2022-10-19/nvdVendor Advisory
- www.secpod.com/blog/oracle-releases-critical-security-updates-january-2023-patch-now/nvdThird Party Advisory
- www.jenkins.io/security/advisory/2022-10-19/ghsaWEB
- www.secpod.com/blog/oracle-releases-critical-security-updates-january-2023-patch-nowghsaWEB
News mentions
0No linked articles in our index yet.