Bug 1819652 (CVE-2019-16538)
Summary: | CVE-2019-16538 jenkins-script-security-plugin: sandbox protection bypass leads to execute arbitrary code in sandboxed scripts | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | abenaiss, aos-bugs, bmontgom, eparis, extras-orphan, java-sig-commits, jburrell, jokerman, mizdebsk, msrb, nstielau, pbhattac, sponnaga, vbobade |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | jenkins-script-security-plugin 1.68 | Doc Type: | If docs needed, set a value |
Doc Text: |
A sandbox bypass flaw was found in the Jenkins Script Security Plugin versions 1.67 and earlier, that are related to the handling of closure default parameter expressions. This flaw allows attackers to execute arbitrary code in sandboxed scripts.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2020-06-17 23:20:41 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1819530, 1819538, 1819544, 1819647, 1819654, 1820007, 1820008, 1873177, 1873182 | ||
Bug Blocks: | 1819705 |
Description
Dhananjay Arunesh
2020-04-01 09:25:36 UTC
Created jenkins-script-security-plugin tracking bugs for this issue: Affects: fedora-30 [bug 1819654] External References: https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1658 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2020:2478 https://access.redhat.com/errata/RHSA-2020:2478 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-16538 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.4 Via RHSA-2020:2737 https://access.redhat.com/errata/RHSA-2020:2737 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.3 Via RHSA-2020:3616 https://access.redhat.com/errata/RHSA-2020:3616 |