Описание
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
The jenkins-plugin-pipeline-build-step fails to check permissions correctly allowing attackers with access to it to specify the triggering of any other project in Jenkins. This potentially gives an attacker access to projects they should not have access to.
Отчет
This issue affects the versions of jenkins-plugin-pipeline-build-step as shipped with Red Hat OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | jenkins-plugin-pipeline-build-step | Will not fix | ||
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | fluentd | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | jenkins-2-plugins | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | kibana | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | rubygem-cool.io | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | rubygem-excon | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | rubygem-faraday | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | rubygem-fluent-plugin-kubernetes_metadata_filter | Fixed | RHBA-2017:2642 | 08.09.2017 |
| Red Hat OpenShift Container Platform 3.6 | rubygem-fluent-plugin-viaq_data_model | Fixed | RHBA-2017:2642 | 08.09.2017 |
Показывать по
Дополнительная информация
Статус:
3.7 Low
CVSS3
Связанные уязвимости
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
Jenkins Build Step Plugin fails to check Item/Build permission
3.7 Low
CVSS3