Bug 1764390 (CVE-2019-10431) - CVE-2019-10431 jenkins-script-security: Sandbox bypass vulnerability in Script Security Plugin
Summary: CVE-2019-10431 jenkins-script-security: Sandbox bypass vulnerability in Scrip...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-10431
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1764391 1764459 1764460 1764461 1764462 1764466
Blocks: 1764392
TreeView+ depends on / blocked
 
Reported: 2019-10-22 23:56 UTC by Pedro Sampaio
Modified: 2021-02-16 21:11 UTC (History)
14 users (show)

Fixed In Version: script-security 1.65
Clone Of:
Environment:
Last Closed: 2019-12-11 13:24:09 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:4055 0 None None None 2019-12-16 13:53:40 UTC
Red Hat Product Errata RHSA-2019:4089 0 None None None 2019-12-17 02:17:43 UTC
Red Hat Product Errata RHSA-2019:4097 0 None None None 2019-12-11 08:37:14 UTC

Description Pedro Sampaio 2019-10-22 23:56:47 UTC
Sandbox protection in Script Security Plugin could be circumvented through default parameter expressions in constructors. This allowed attackers able to specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.

References:

https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579

Comment 1 Pedro Sampaio 2019-10-22 23:57:00 UTC
Created jenkins-script-security-plugin tracking bugs for this issue:

Affects: fedora-all [bug 1764391]

Comment 6 errata-xmlrpc 2019-12-11 08:37:12 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.2

Via RHSA-2019:4097 https://access.redhat.com/errata/RHSA-2019:4097

Comment 7 Product Security DevOps Team 2019-12-11 13:24:09 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-10431

Comment 8 errata-xmlrpc 2019-12-16 13:53:38 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 3.11

Via RHSA-2019:4055 https://access.redhat.com/errata/RHSA-2019:4055

Comment 9 errata-xmlrpc 2019-12-17 02:17:41 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.1

Via RHSA-2019:4089 https://access.redhat.com/errata/RHSA-2019:4089

Comment 10 Eric Christensen 2020-05-05 13:05:56 UTC
External References:

https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579


Note You need to log in before you can comment on or make changes to this bug.