Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1446128 - (CVE-2017-1000355) CVE-2017-1000355 jenkins: Java crash when trying to instantiate void/Void (SECURITY-503)
CVE-2017-1000355 jenkins: Java crash when trying to instantiate void/Void (SE...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170426,repor...
: Security
Depends On: 1446133 1446134
Blocks: 1395176 1446135
  Show dependency treegraph
 
Reported: 2017-04-27 06:00 EDT by Adam Mariš
Modified: 2018-06-29 18:20 EDT (History)
14 users (show)

See Also:
Fixed In Version: jenkins 2.46.2, jenkins 2.57
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2017-04-27 06:00:58 EDT
Jenkins uses the XStream library to serialize and deserialize XML. Its maintainer recently published a security vulnerability that allows anyone able to provide XML to Jenkins for processing using XStream to crash the Java process. In Jenkins this typically applies to users with permission to create or configure items (jobs), views, or agents.

Jenkins now prohibits the attempted deserialization of void / Void that results in a crash.

Affected versions:

    All Jenkins main line releases up to and including 2.56
    All Jenkins LTS releases up to and including 2.46.1

Fixed in:

    Jenkins main line users should update to 2.57
    Jenkins LTS users should update to 2.46.2

External References:

https://jenkins.io/security/advisory/2017-04-26/#xstream-java-crash-when-trying-to-instantiate-void-void
http://www.openwall.com/lists/oss-security/2017/04/03/4
Comment 1 Adam Mariš 2017-04-27 06:01:25 EDT
Acknowledgments:

Name: the Jenkins project
Comment 2 Adam Mariš 2017-04-27 06:08:46 EDT
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1446133]
Affects: openshift-1 [bug 1446134]
Comment 3 Norman Gaywood 2017-05-18 21:29:43 EDT
Any update on these issues?

The security team here are wanting me to make their scan notices about this go away.

Note You need to log in before you can comment on or make changes to this bug.