← Back to browse · API

CVE-2024-34144

Severity
CRITICAL
CVSS
9.8
EPSS
0.48081
Risk score
56.03
CISA KEV
No
PoC
No
Published
2024-05-02
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-1789, GHSA-V63G-V339-2673
Products
Jenkins Project:Jenkins Script Security Plugin 0 ≤1335.vf07d9ce377a_e
Sources
euvd EUVD-2024-1789

Description

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

References