Описание
RCE vulnerability in RadarGun Plugin
RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution vulnerability exploitable by users able to configure RadarGun Plugin’s build step.
RadarGun Plugin 1.8 configures its YAML parser to only instantiate safe types.
Пакеты
Наименование
org.jenkins-ci.plugins:radargun
maven
Затронутые версииВерсия исправления
< 1.8
1.8
Связанные уязвимости
CVSS3: 8.8
nvd
почти 6 лет назад
Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.