Описание
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
A flaw was found in the Jenkins Script Security plugin through version 1.50. The fix for CVE-2019-1003000 was found to be incomplete. Script Security sandbox protection could be circumvented during the script compilation phase by applying AST transforming annotations such as @Grab to source code elements. This affected an HTTP endpoint used to validate a user-submitted Groovy script that was not covered in the 2019-01-08 fix for SECURITY-1266 and allowed users with Overall/Read permission to bypass the sandbox protection and execute arbitrary code on the Jenkins master. The affected HTTP endpoint now applies a safe Groovy compiler configuration prohibiting unsafe AST transforming annotations. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.2 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.3 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.4 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.5 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.6 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.7 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 3.9 | jenkins-plugin-script-security | Will not fix | ||
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Not affected | ||
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Fixed | RHSA-2019:0739 | 10.04.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
Уязвимость компонента SecureGroovyScript.java плагина Jenkins Script Security, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3