Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1003005

Опубликовано: 29 янв. 2019
Источник: redhat
CVSS3: 8.8
EPSS Высокий

Описание

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

A flaw was found in the Jenkins Script Security plugin through version 1.50. The fix for CVE-2019-1003000 was found to be incomplete. Script Security sandbox protection could be circumvented during the script compilation phase by applying AST transforming annotations such as @Grab to source code elements. This affected an HTTP endpoint used to validate a user-submitted Groovy script that was not covered in the 2019-01-08 fix for SECURITY-1266 and allowed users with Overall/Read permission to bypass the sandbox protection and execute arbitrary code on the Jenkins master. The affected HTTP endpoint now applies a safe Groovy compiler configuration prohibiting unsafe AST transforming annotations. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.2jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.3jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.4jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.5jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.6jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsFixedRHSA-2019:073910.04.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-96
https://bugzilla.redhat.com/show_bug.cgi?id=1670283jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin (SECURITY-1292)

EPSS

Процентиль: 99%
0.74186
Высокий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 7 лет назад

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

CVSS3: 8.8
github
больше 3 лет назад

Sandbox Bypass in Script Security Plugin

CVSS3: 8.8
fstec
около 7 лет назад

Уязвимость компонента SecureGroovyScript.java плагина Jenkins Script Security, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.74186
Высокий

8.8 High

CVSS3