CVE-2017-1000107
Summary
| CVE | CVE-2017-1000107 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-05 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Script Security | 1.30 | All | All | All |
| Application | Jenkins | Script Security | 1.30 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jenkins Security Advisory 2017-08-07 | CONFIRM | jenkins.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997350 Java (Maven) Security Update for org.jenkins-ci.plugins:script-security (GHSA-h7rx-r733-7x7r)