QID 995815
Date Published: 2023-11-06
QID 995815: Java (Maven) Security Update for com.splunk.splunkins:splunk-devops (GHSA-cjr8-5rw4-wh65)
Jenkins Splunk Plugin has a form validation HTTP endpoint used to validate a user-submitted Groovy script through compilation, which was not subject to sandbox protection. This allowed attackers with Overall/Read access to execute arbitrary code on the Jenkins controller by applying AST transforming annotations such as @Grab to source code elements.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cjr8-5rw4-wh65 for updates and patch information.
Vendor References
- GHSA-cjr8-5rw4-wh65 -
github.com/advisories/GHSA-cjr8-5rw4-wh65
CVEs related to QID 995815
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cjr8-5rw4-wh65 | com.splunk.splunkins:splunk-devops |
|