Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1620337 - (CVE-2018-1999042) CVE-2018-1999042 jenkins: Deserialization of URL objects with host components
CVE-2018-1999042 jenkins: Deserialization of URL objects with host components
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180815,reported=2...
: Security
Depends On: 1620338
Blocks: 1620339
  Show dependency treegraph
 
Reported: 2018-08-23 00:26 EDT by Sam Fowler
Modified: 2018-10-30 19:31 EDT (History)
13 users (show)

See Also:
Fixed In Version: jenkins 2.121.3, jenkins 2.138
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-08-23 00:26:19 EDT
Jenkins before LTS version 2.121.3 and weekly version 2.138 allow deserialization of URL objects via Remoting (agent communication) and XStream.

This could in rare cases be used by attackers to have Jenkins look up specified hosts' DNS records.


External Reference:

https://jenkins.io/security/advisory/2018-08-15/#SECURITY-637
Comment 1 Sam Fowler 2018-08-23 00:26:40 EDT
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1620338]
Comment 4 Jason Shepherd 2018-10-30 19:25:04 EDT
The communication between Jenkins master and slave happens using the encrypted Jenkins Remoting JNLP4 protocol, [1]. Also the master exposes the JNLP port as a service, not a route. So it should not be accessible outside of the project unless the ovs-subnet plugin is in use.

Because of these reasons the impact of the flaw itself if 'Low', Product Security have decided not to fix this issue in OCP 3.10 and earlier. Upgrade to OCP 3.11 to obtain a fix for this issue.

[1] https://github.com/jenkinsci/remoting/blob/master/docs/protocols.md#jnlp4-connect

Note You need to log in before you can comment on or make changes to this bug.