Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1003024

Опубликовано: 19 фев. 2019
Источник: redhat
CVSS3: 8.8

Описание

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

A flaw was found in the Jenkins script security sandbox. The previously implemented script security sandbox protections prohibiting the use of unsafe AST transforming annotations such as @Grab could be circumvented through use of various Groovy language features including the use of AnnotationCollector, import aliasing, and referencing annotation types using their full class name. This allows users with Overall/Read permission, or the ability to control Jenkinsfile or sandboxed Pipeline shared library contents in SCM, to bypass the sandbox protection and execute arbitrary code on the Jenkins master. The highest threat from this vulnerability is to data confidentiality and integrity and system availability.

Отчет

This flaw affects the jenkins-2-plugins RPM which is installed in the openshift3/jenkins-2-rhel7 container image. Security updates for this image are only released for versions 3.11 and 4.x of OpenShift Container Platform. The 3.11 version of the openshift3/jenkins-2-rhel7 container image is supported for use with previous versions of OpenShift Container Platform up to 3.4. For more information, refer to the OpenShift Jenkins README: https://github.com/openshift/jenkins/blob/master/README.md#jenkins-security-advisories-the-master-image-from-this-repository-and-the-oc-binary

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.10jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.4jenkins-plugin-script-securityOut of support scope
Red Hat OpenShift Container Platform 3.5jenkins-plugin-script-securityOut of support scope
Red Hat OpenShift Container Platform 3.6jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-96
https://bugzilla.redhat.com/show_bug.cgi?id=1684556jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin (SECURITY-1320)

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

CVSS3: 8.8
debian
больше 7 лет назад

A sandbox bypass vulnerability exists in Jenkins Script Security Plugi ...

CVSS3: 8.8
github
больше 4 лет назад

Jenkins Script Security Plugin sandbox bypass vulnerability

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость компонента RejectASTTransformsCustomizer.java плагина Jenkins Script Security, позволяющая нарушителю выполнить произвольный код

8.8 High

CVSS3