Jenkins Multiple Security Bypass Vulnerabilities
BID:106681
Info
Jenkins Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 106681 |
| Class: | Design Error |
| CVE: |
CVE-2019-1003000 CVE-2019-1003001 CVE-2019-1003002 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2019 12:00AM |
| Updated: | Jan 08 2019 12:00AM |
| Credit: | Orange Tsai(@orange_8361) from DEVCORE. |
| Vulnerable: |
Jenkins Script Security 1.9 Jenkins Script Security 1.8 Jenkins Script Security 1.7 Jenkins Script Security 1.6 Jenkins Script Security 1.5 Jenkins Script Security 1.49 Jenkins Script Security 1.48 Jenkins Script Security 1.47 Jenkins Script Security 1.46 Jenkins Script Security 1.45 Jenkins Script Security 1.44 Jenkins Script Security 1.43 Jenkins Script Security 1.42 Jenkins Script Security 1.41 Jenkins Script Security 1.40 Jenkins Script Security 1.4 Jenkins Script Security 1.39 Jenkins Script Security 1.38 Jenkins Script Security 1.31 Jenkins Script Security 1.30 Jenkins Script Security 1.3 Jenkins Script Security 1.29 Jenkins Script Security 1.28 Jenkins Script Security 1.27 Jenkins Script Security 1.26 Jenkins Script Security 1.25 Jenkins Script Security 1.24 Jenkins Script Security 1.23 Jenkins Script Security 1.22 Jenkins Script Security 1.21 Jenkins Script Security 1.20 Jenkins Script Security 1.2 Jenkins Script Security 1.19 Jenkins Script Security 1.18 Jenkins Script Security 1.17 Jenkins Script Security 1.16 Jenkins Script Security 1.15 Jenkins Script Security 1.14 Jenkins Script Security 1.13 Jenkins Script Security 1.12 Jenkins Script Security 1.11 Jenkins Script Security 1.10 Jenkins Script Security 1.1 Jenkins Script Security 1.0 Jenkins Pipeline: Groovy 2.36.1 Jenkins Pipeline: Groovy 2.61 Jenkins Pipeline: Groovy 2.60 Jenkins Pipeline: Groovy 2.59 Jenkins Pipeline: Groovy 2.58 Jenkins Pipeline: Groovy 2.57 Jenkins Pipeline: Groovy 2.56 Jenkins Pipeline: Groovy 2.55 Jenkins Pipeline: Groovy 2.54 Jenkins Pipeline: Groovy 2.53 Jenkins Pipeline: Groovy 2.52 Jenkins Pipeline: Groovy 2.51 Jenkins Pipeline: Groovy 2.50 Jenkins Pipeline: Groovy 2.49 Jenkins Pipeline: Groovy 2.48 Jenkins Pipeline: Groovy 2.47 Jenkins Pipeline: Groovy 2.46 Jenkins Pipeline: Groovy 2.45 Jenkins Pipeline: Groovy 2.44 Jenkins Pipeline: Groovy 2.43 Jenkins Pipeline: Groovy 2.42 Jenkins Pipeline: Groovy 2.41 Jenkins Pipeline: Groovy 2.40 Jenkins Pipeline: Groovy 2.36 Jenkins Pipeline: Declarative 1.3.4 Jenkins Pipeline: Declarative 1.3.3 Jenkins Pipeline: Declarative 1.3.2 Jenkins Pipeline: Declarative 1.3.1 Jenkins Pipeline: Declarative 1.2.9 Jenkins Pipeline: Declarative 1.2.8 Jenkins Pipeline: Declarative 1.2.7 Jenkins Pipeline: Declarative 1.2.6 Jenkins Pipeline: Declarative 1.2.5 Jenkins Pipeline: Declarative 1.2.4 Jenkins Pipeline: Declarative 1.2.3 Jenkins Pipeline: Declarative 1.2.2 Jenkins Pipeline: Declarative 1.2.1 Jenkins Pipeline: Declarative 1.3 Jenkins Pipeline: Declarative 1.2 |
| Not Vulnerable: |
Jenkins Script Security 1.50 Jenkins Pipeline: Groovy 2.61.1 Jenkins Pipeline: Declarative 1.3.4.1 |
Discussion
Jenkins Multiple Security Bypass Vulnerabilities
Jenkins is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions to perform unauthorized actions or to execute arbitrary code within the context of the application.
The following versions of Jenkins are vulnerable:
Jenkins Pipeline: Declarative Plugin 1.3.4 and prior.
Jenkins Pipeline: Groovy Plugin 2.61 and prior.
Jenkins Script Security Plugin 1.49 and prior.
Jenkins is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions to perform unauthorized actions or to execute arbitrary code within the context of the application.
The following versions of Jenkins are vulnerable:
Jenkins Pipeline: Declarative Plugin 1.3.4 and prior.
Jenkins Pipeline: Groovy Plugin 2.61 and prior.
Jenkins Script Security Plugin 1.49 and prior.
Exploit / POC
Jenkins Multiple Security Bypass Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Jenkins Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Jenkins Multiple Security Bypass Vulnerabilities
References:
References:
- Pipeline: Declarative Github Repository (Github)
- Pipeline: Declarative Plugin Page (Jenkins)
- Pipeline: Groovy Plugin Github Repository (Github)
- Pipeline: Groovy Plugin Page (Jenkins)
- Script Security Github Repository (Github)
- Script Security Plugin Homepage (Jenkins)
- jenkins home page (jenkins)
- Jenkins Security Advisory 2019-01-08 (Jenkins)