Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv6f-rcv6-6q3x

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Improper handling of REST API XML deserialization errors in Jenkins

Jenkins provides XML REST APIs to configure views, jobs, and other items. When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old Data Monitor. If an administrator discards the old data, some erroneous data submitted to these endpoints may be persisted.

This allows attackers with View/Create, Job/Create, Agent/Create, or their respective */Configure permissions to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects when discarded by an administrator.\n\nJenkins 2.275, LTS 2.263.2 does not record submissions from users in Old Data Monitor anymore.

In case of problems, the Java system properties hudson.util.RobustReflectionConverter.recordFailuresForAdmins and hudson.util.RobustReflectionConverter.recordFailuresForAllAuthentications can be set to true to record configuration data submissions from administrators or all users, partially or completely disabling this fix.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.263.1

2.263.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.264, <= 2.274

2.275

EPSS

Процентиль: 74%
0.00835
Низкий

8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8
redhat
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.

CVSS3: 8
nvd
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.

CVSS3: 8
debian
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers wi ...

EPSS

Процентиль: 74%
0.00835
Низкий

8 High

CVSS3

Дефекты

CWE-502