← Vulnerability feed

Vulnerability record · CVE-2024-34144 · published 2 May 2024

CVE-2024-34144: Jenkins Script Security Plugin sandbox bypass via crafted constructors

Jenkins · Script Security

Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier fails to properly restrict crafted constructor bodies, allowing a sandbox bypass. An attacker who can define and run sandboxed scripts, including Pipelines, can escape the sandbox and run arbitrary code in the Jenkins controller JVM.

9.8 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-693 · CWE-693
9.8CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 critical with high EPSS and arbitrary code execution on the Jenkins controller, though exploitation requires script-definition permission.

What it is

Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier fails to properly restrict crafted constructor bodies, allowing a sandbox bypass. An attacker who can define and run sandboxed scripts, including Pipelines, can escape the sandbox and run arbitrary code in the Jenkins controller JVM.

Impact

An attacker gains arbitrary code execution in the context of the Jenkins controller JVM, which can lead to full compromise of the Jenkins instance and its credentials.

Attack surface

Reached over the network through Jenkins script or Pipeline execution; the CVSS vector indicates no authentication or user interaction, but the description states the attacker needs permission to define and run sandboxed scripts, so some level of script-definition access is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.48081 (98.8th percentile), indicating a high likelihood of exploitation activity; references are vendor advisory and mailing list only, with no public exploit tag.

What to do

  • Upgrade Jenkins Script Security Plugin to a version later than 1335.vf07d9ce377a_e per the vendor advisory.
  • Restrict who can define and run sandboxed scripts and Pipelines to trusted users only.
  • Review and reduce permissions granted to Jenkins users and service accounts that can submit scripts.
  • Monitor the Jenkins controller for unexpected process or command execution after script submissions.

Detection

  • Audit Jenkins logs for script or Pipeline submissions that create unusual constructor bodies or unexpected class instantiation.
  • Alert on child processes or command execution spawned by the Jenkins controller JVM.
  • Track Script Security Plugin versions across controllers and flag any at or below 1335.vf07d9ce377a_e.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-34144 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-1003029Jenkins Script Security Plugin sandbox bypass allows code executionThe Jenkins Script Security Plugin 1.53 and earlier fails to properly enforce its Groovy sandbox in GroovySandbox.java and SecureGroovyScript.java, l…KEVEPSS 74%analysed9.9CVE-2022-43401Jenkins script security vulnerabilityA sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v77…EPSS 1.3%9.9CVE-2022-43403Jenkins script security vulnerabilityA sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and ea…EPSS 1.6%9.9CVE-2022-43404Jenkins script security vulnerabilityA sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security …EPSS 1.2%9.9CVE-2020-2279Jenkins script security vulnerabilityA sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to pro…EPSS 2.1%9.9CVE-2019-10431Jenkins script security code injection vulnerabilityA sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru…EPSS 2.7%9.8CVE-2019-1003040Jenkins script security vulnerabilityA sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri…EPSS 3.4%8.8CVE-2026-92122Jenkins script security vulnerabilityJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script c…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2024-34144), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.