Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3g4-9xfv-wq9v

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Arbitrary code execution due to incomplete sandbox protection in Pipeline: Supporting APIs Plugin

Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-support

maven
Затронутые версииВерсия исправления

<= 2.17

2.18

EPSS

Процентиль: 79%
0.01296
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
redhat
около 8 лет назад

Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.

CVSS3: 8.8
nvd
почти 8 лет назад

Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.

EPSS

Процентиль: 79%
0.01296
Низкий

8.8 High

CVSS3

Дефекты

CWE-502