CVE-2024-34144

CRITICAL

Jenkins Script Security Plugin <1335.vf07d9ce377a_e - Privilege Esc...

Title source: llm

Description

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Exploits (1)

nomisec WORKING POC 2 stars
by MXWXZ · poc
https://github.com/MXWXZ/CVE-2024-34144

Scores

CVSS v3 9.8
EPSS 0.5005
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-693
Status published

Affected Products (2)

jenkins/script_security < 1335.vf07d9ce377a_e
org.jenkins-ci.plugins/script-security < 1336.vf33aMaven

Timeline

Published May 02, 2024
Tracked Since Feb 18, 2026