PT-2019-2298 · Jenkins · Jenkins Script Security Plugin+1

·

CVE-2019-1003024

·

Publicado

2019-02-19

·

Atualizado

2023-10-25

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Script Security Plugin versions 1.52 and earlier
Description A sandbox bypass issue exists that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM by providing a Groovy script to an HTTP endpoint. The vulnerability is related to errors in processing AST annotations in the RejectASTTransformsCustomizer.java component. It can be exploited by remotely bypassing sandbox protections, which were previously implemented to prohibit the use of unsafe AST transforming annotations. The protections could be circumvented using various Groovy language features, including the use of AnnotationCollector, import aliasing, and referencing annotation types using their full class name.
Recommendations For Jenkins Script Security Plugin versions 1.52 and earlier, consider updating to a version that prohibits the use of AnnotationCollector in sandboxed scripts and rejects prohibited annotations during the compilation phase. As a temporary workaround, restrict access to the RejectASTTransformsCustomizer.java component and avoid using unsafe AST transforming annotations such as @Grab in Groovy scripts.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02069
CVE-2019-1003024
GHSA-JGPM-2862-Q5M8
RHSA-2019:0739

Produtos afetados

Jenkins
Jenkins Script Security Plugin