peter bassill · operator
$ cve CVE-2024-34144 JSON

CVE-2024-34144

9.8
CRITICAL · CVSS 3.1 · EPSS 48.1% (pctl 99)

Patch early

EPSS 48.1% — above the 10% action threshold.

Description

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS48.08% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-693
On CISA KEVno
Public exploitnone known
Published2024-05-02
Last modified2026-06-17

Affected (1)

VendorProduct
jenkinsscript security

References

→ the Explorer  ·  watch your stack  ·  NVD