jenkins-plugin-pipeline-model-definition: Sandbox Bypass in Pipeline: Declarative
Published Jan 22, 2019
8.8
HIGHCVSS 3.1
EPSS 81.36%
Description
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
Affected products
-
- Version 1.3.3 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Pipeline: Declarative Plugin | n/a |
|
Configuration 2
- 3.11
No data.
Red Hat OpenShift Container Platform 3.11
atomic-enterprise-service-catalog-1:3.11.82-1.git.1673.133961e.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.82-1.git.0.08bc31b.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-cluster-autoscaler-0:3.11.82-1.git.0.efb6af0.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-descheduler-0:3.11.82-1.git.300.89765c9.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-dockerregistry-0:3.11.82-1.git.452.0ce6383.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-metrics-server-0:3.11.82-1.git.52.2fdca3f.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-node-problem-detector-0:3.11.82-1.git.254.a448936.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-service-idler-0:3.11.82-1.git.14.e353758.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console-0:3.11.82-1.git.355.5e8b1d9.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
golang-github-openshift-oauth-proxy-0:3.11.82-1.git.425.7cac034.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-alertmanager-0:3.11.82-1.git.0.3bf41ce.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-node_exporter-0:3.11.82-1.git.1063.48444e8.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-prometheus-0:3.11.82-1.git.5027.9d24833.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
haproxy-0:1.8.17-3.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.150.2.1549032159-1.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1549642489-1.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
openshift-ansible-0:3.11.82-3.git.0.9718d0a.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-autoheal-0:3.11.82-1.git.219.0b5aff4.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-cluster-capacity-0:3.11.82-1.git.380.cf11c51.el7
Fixed · RHBA-2019:0326
Red Hat OpenShift Container Platform 3.10
jenkins-plugin-pipeline-model-definition
Affected
Red Hat OpenShift Container Platform 3.2
jenkins-plugin-pipeline-model-definition
Not affected
Red Hat OpenShift Container Platform 3.3
jenkins-plugin-pipeline-model-definition
Not affected
Red Hat OpenShift Container Platform 3.4
jenkins-plugin-pipeline-model-definition
Not affected
Red Hat OpenShift Container Platform 3.5
jenkins-plugin-pipeline-model-definition
Out of support scope
Red Hat OpenShift Container Platform 3.6
jenkins-plugin-pipeline-model-definition
Affected
Red Hat OpenShift Container Platform 3.7
jenkins-plugin-pipeline-model-definition
Affected
Red Hat OpenShift Container Platform 3.9
jenkins-plugin-pipeline-model-definition
Affected
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog-1:3.11.82-1.git.1673.133961e.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.82-1.git.0.08bc31b.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler-0:3.11.82-1.git.0.efb6af0.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler-0:3.11.82-1.git.300.89765c9.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry-0:3.11.82-1.git.452.0ce6383.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server-0:3.11.82-1.git.52.2fdca3f.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector-0:3.11.82-1.git.254.a448936.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-service-idler-0:3.11.82-1.git.14.e353758.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console-0:3.11.82-1.git.355.5e8b1d9.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-openshift-oauth-proxy-0:3.11.82-1.git.425.7cac034.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-alertmanager-0:3.11.82-1.git.0.3bf41ce.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-node_exporter-0:3.11.82-1.git.1063.48444e8.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-prometheus-0:3.11.82-1.git.5027.9d24833.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | haproxy-0:1.8.17-3.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.150.2.1549032159-1.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1549642489-1.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | openshift-ansible-0:3.11.82-3.git.0.9718d0a.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-autoheal-0:3.11.82-1.git.219.0b5aff4.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-cluster-capacity-0:3.11.82-1.git.380.cf11c51.el7 | Fixed | RHBA-2019:0326 |
| Red Hat OpenShift Container Platform 3.10 | jenkins-plugin-pipeline-model-definition | Affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | jenkins-plugin-pipeline-model-definition | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | jenkins-plugin-pipeline-model-definition | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins-plugin-pipeline-model-definition | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins-plugin-pipeline-model-definition | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins-plugin-pipeline-model-definition | Affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins-plugin-pipeline-model-definition | Affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins-plugin-pipeline-model-definition | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- http://packetstormsecurity.com/files/152132/Jenkins-ACL-Bypass-Metaprogramming-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/jenkins_metaprogramming x_refsource_MISCThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:0326 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:0327 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-1003002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1669508 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5729 Advisory
- https://github.com/advisories/GHSA-x6jx-cxg3-mggh Advisory
- https://github.com/jenkinsci/pipeline-model-definition-plugin/commit/083abd96e68fd89f556a0cd53db5f878dbf09b92
- https://jenkins.io/security/advisory/2019-01-08/
- https://jenkins.io/security/advisory/2019-01-08/#SECURITY-1266 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-1003002
- https://www.cve.org/CVERecord?id=CVE-2019-1003002
- https://www.exploit-db.com/exploits/46572/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.