High severity8.8NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2023-24422
CVE-2023-24422
Description
A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:script-securityMaven | < 1229.v4880b | 1229.v4880b |
Affected products
3unspecified+ 1 more
- (no CPE)range: unspecified
- cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*range: <1229.v4880b_b_e905a_6
Patches
Vulnerability mechanics
References
4News mentions
1- Jenkins Security Advisory 2023-01-24Jenkins Security Advisories · Jan 24, 2023