Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w2w-fwpf-9m4h

Опубликовано: 16 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure

Jenkins Pipeline: Deprecated Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same workspace directory for all checkouts of Pipeline libraries with the same name regardless of the SCM being used and the source of the library configuration.

This allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global Pipeline library already exists.

Pipeline: Deprecated Groovy Libraries Plugin 561.va_ce0de3c2d69 uses distinct checkout directories per SCM for Pipeline libraries.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-cps-global-lib

maven
Затронутые версииВерсия исправления

<= 552.vd9cc05b8a2e1

561.va_ce0de3c2d69

EPSS

Процентиль: 64%
0.00469
Низкий

8.8 High

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 8.8
redhat
почти 4 года назад

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global Pipeline library already exists.

CVSS3: 8.8
nvd
почти 4 года назад

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global Pipeline library already exists.

EPSS

Процентиль: 64%
0.00469
Низкий

8.8 High

CVSS3

Дефекты

CWE-693