Bug 1819697 (CVE-2019-10393)

Summary: CVE-2019-10393 jenkins-script-security-plugin: handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abenaiss, aos-bugs, bmontgom, eparis, extras-orphan, java-sig-commits, jburrell, jokerman, mizdebsk, msrb, nstielau, pbhattac, sponnaga, vbobade
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: jenkins-script-security-plugin 1.63 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-02 04:31:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1819699    
Bug Blocks: 1819655    

Description Dhananjay Arunesh 2020-04-01 10:43:25 UTC
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.

Reference:
http://www.openwall.com/lists/oss-security/2019/09/12/2

Comment 1 Dhananjay Arunesh 2020-04-01 10:44:08 UTC
Created jenkins-script-security-plugin tracking bugs for this issue:

Affects: fedora-30 [bug 1819699]

Comment 2 Sam Fowler 2020-04-02 01:47:33 UTC
External References:

https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1538

Comment 3 Sam Fowler 2020-04-02 01:48:05 UTC
Fixed in OpenShift Container Platform 3.11 in the below advisory:

https://access.redhat.com/errata/RHSA-2019:4055

Comment 4 Sam Fowler 2020-04-02 01:55:01 UTC
Fixed in OpenShift Container Platform 4.2 in the below advisory:

https://access.redhat.com/errata/RHSA-2019:4097

Comment 5 Product Security DevOps Team 2020-04-02 04:31:51 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-10393