Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000089

Опубликовано: 10 июл. 2017
Источник: redhat
CVSS3: 3.7

Описание

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

The jenkins-plugin-pipeline-build-step fails to check permissions correctly allowing attackers with access to it to specify the triggering of any other project in Jenkins. This potentially gives an attacker access to projects they should not have access to.

Отчет

This issue affects the versions of jenkins-plugin-pipeline-build-step as shipped with Red Hat OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkins-plugin-pipeline-build-stepWill not fix
Red Hat OpenShift Container Platform 3.6atomic-openshiftFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6fluentdFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6jenkins-2-pluginsFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6kibanaFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6rubygem-cool.ioFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6rubygem-exconFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6rubygem-faradayFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6rubygem-fluent-plugin-kubernetes_metadata_filterFixedRHBA-2017:264208.09.2017
Red Hat OpenShift Container Platform 3.6rubygem-fluent-plugin-viaq_data_modelFixedRHBA-2017:264208.09.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1471050jenkins-plugin-pipeline-build-step: Missing check of Item/Build permission (SECURITY-433)

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 8 лет назад

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

CVSS3: 5.3
github
больше 3 лет назад

Jenkins Build Step Plugin fails to check Item/Build permission

3.7 Low

CVSS3