Bug 1443409 - jenkins-task-reactor: Running arbitrary Groovy code in Jenskin JVM via Reactor Event (SECURITY-487)
Summary: jenkins-task-reactor: Running arbitrary Groovy code in Jenskin JVM via Reacto...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1443535 1471343
Blocks: 1395176 1443413
TreeView+ depends on / blocked
 
Reported: 2017-04-19 08:19 UTC by Adam Mariš
Modified: 2021-10-21 11:52 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-21 11:52:55 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2017-04-19 08:19:48 UTC
Reactor plugin allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM by defining a Reactor Script that will be run when a Reactor Event triggers, effectively elevating privileges to Overall/Run Scripts.

Affects all versions.

Comment 1 Adam Mariš 2017-04-19 08:20:00 UTC
External References:

https://jenkins.io/security/advisory/2017-04-10/#reactor-plugin

Comment 2 Adam Mariš 2017-04-19 12:42:26 UTC
Created jenkins-task-reactor tracking bugs for this issue:

Affects: fedora-all [bug 1443535]


Note You need to log in before you can comment on or make changes to this bug.