Описание
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
A flaw was found in the Jenkins Workflow Remote Loader plugin. An unsafe whitelist entry was made that allowed invoking arbitrary methods and bypassing sandbox protection. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | jenkins-plugin-workflow-remote-loader | Will not fix | ||
| Red Hat OpenShift Container Platform 3.6 | jenkins-plugin-workflow-remote-loader | Will not fix | ||
| Red Hat OpenShift Container Platform 3.7 | jenkins-plugin-workflow-remote-loader | Will not fix | ||
| Red Hat OpenShift Container Platform 3.9 | jenkins-plugin-workflow-remote-loader | Will not fix | ||
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog | Fixed | RHBA-2019:1605 | 26.06.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler | Fixed | RHBA-2019:1605 | 26.06.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler | Fixed | RHBA-2019:1605 | 26.06.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry | Fixed | RHBA-2019:1605 | 26.06.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server | Fixed | RHBA-2019:1605 | 26.06.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector | Fixed | RHBA-2019:1605 | 26.06.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
Unsafe entry in Script Security list of approved signatures in Pipeline Remote Loader Plugin
Уязвимость плагина Jenkins Pipeline Remote Loader, связанная с недостатками механизма защиты данных, позволяющая нарушителю обойти ограничения песочницы
EPSS
8.8 High
CVSS3