Vulnerability record · CVE-2024-34144 · published 2 May 2024
CVE-2024-34144: Jenkins Script Security Plugin sandbox bypass via crafted constructors
Jenkins · Script Security
Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier fails to properly restrict crafted constructor bodies, allowing a sandbox bypass. An attacker who can define and run sandboxed scripts, including Pipelines, can escape the sandbox and run arbitrary code in the Jenkins controller JVM.
Description
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 critical with high EPSS and arbitrary code execution on the Jenkins controller, though exploitation requires script-definition permission.
What it is
Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier fails to properly restrict crafted constructor bodies, allowing a sandbox bypass. An attacker who can define and run sandboxed scripts, including Pipelines, can escape the sandbox and run arbitrary code in the Jenkins controller JVM.
Impact
An attacker gains arbitrary code execution in the context of the Jenkins controller JVM, which can lead to full compromise of the Jenkins instance and its credentials.
Attack surface
Reached over the network through Jenkins script or Pipeline execution; the CVSS vector indicates no authentication or user interaction, but the description states the attacker needs permission to define and run sandboxed scripts, so some level of script-definition access is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.48081 (98.8th percentile), indicating a high likelihood of exploitation activity; references are vendor advisory and mailing list only, with no public exploit tag.
What to do
- Upgrade Jenkins Script Security Plugin to a version later than 1335.vf07d9ce377a_e per the vendor advisory.
- Restrict who can define and run sandboxed scripts and Pipelines to trusted users only.
- Review and reduce permissions granted to Jenkins users and service accounts that can submit scripts.
- Monitor the Jenkins controller for unexpected process or command execution after script submissions.
Detection
- Audit Jenkins logs for script or Pipeline submissions that create unusual constructor bodies or unexpected class instantiation.
- Alert on child processes or command execution spawned by the Jenkins controller JVM.
- Track Script Security Plugin versions across controllers and flag any at or below 1335.vf07d9ce377a_e.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/05/02/3 | Mailing List |
| https://www.jenkins.io/security/advisory/2024-05-02/#SECURITY-3341 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/05/02/3 | Mailing List |
| https://www.jenkins.io/security/advisory/2024-05-02/#SECURITY-3341 | Vendor Advisory |
Track CVE-2024-34144 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-34144), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.