Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2xvx-rw9p-xgfc | Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Jenkins Pipeline: Groovy Plugin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T07:03:40.031Z
Reserved: 2022-05-16T00:00:00
Link: CVE-2022-30945
No data.
Status : Modified
Published: 2022-05-17T15:15:08.647
Modified: 2024-11-21T07:03:36.430
Link: CVE-2022-30945
OpenCVE Enrichment
No data.
Github GHSA