Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1620344 - (CVE-2018-1999044) CVE-2018-1999044 jenkins: Cron expression form validation could enter infinite loop, potentially resulting in denial of service
CVE-2018-1999044 jenkins: Cron expression form validation could enter infinit...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180815,repor...
: Security
Depends On: 1620345
Blocks: 1620339
  Show dependency treegraph
 
Reported: 2018-08-23 00:36 EDT by Sam Fowler
Modified: 2018-10-30 22:05 EDT (History)
13 users (show)

See Also:
Fixed In Version: jenkins 2.121.3, jenkins 2.138
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-08-23 00:36:34 EDT
Jenkins before LTS version 2.121.3 and weekly version 2.138 are vulnerable to a denial of service.

The form validation for cron expressions (e.g. "Poll SCM", "Build periodically") could enter infinite loops when cron expressions only matching certain rare dates were entered, blocking request handling threads indefinitely.


External Reference:

https://jenkins.io/security/advisory/2018-08-15/#SECURITY-790
Comment 1 Sam Fowler 2018-08-23 00:36:52 EDT
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1620345]
Comment 3 Jason Shepherd 2018-10-30 22:04:09 EDT
OpenShift Container Platform 3.x uses cgroups to limit the CPU allocated to pods by default. Any denial of service caused by this issue would be limited to the user's own Jenkins instance and won't affect other users on the same compute node.
Comment 4 Jason Shepherd 2018-10-30 22:05:18 EDT
Statement:

Users of OpenShift Container Platform 3.x should upgrade to 3.11 to pick up a fix for this issue.

Note You need to log in before you can comment on or make changes to this bug.