Description
A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2824%20%282%29
Related Vulnerabilities
CVE-2020-2216 Vulnerability in maven package org.jenkins-ci.plugins:zephyr-for-jira-test-management
CVE-2021-3856 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-7777 Vulnerability in npm package jsen
CVE-2020-2194 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2019-17563 Vulnerability in maven package org.apache.tomcat:tomcat-catalina