CVE-2024-34144
9.8
CRITICAL · CVSS 3.1 · EPSS 48.1% (pctl 99)
Patch early
EPSS 48.1% — above the 10% action threshold.
Description
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 48.08% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-693 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2024-05-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| jenkins | script security |
References
→ the Explorer · watch your stack · NVD