QID 997291
Date Published: 2024-02-20
QID 997291: Java (Maven) Security Update for org.jenkins-ci.plugins.workflow:workflow-support (GHSA-p3g4-9xfv-wq9v)
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-p3g4-9xfv-wq9v for updates and patch information.
Vendor References
- GHSA-p3g4-9xfv-wq9v -
github.com/advisories/GHSA-p3g4-9xfv-wq9v
CVEs related to QID 997291
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p3g4-9xfv-wq9v | org.jenkins-ci.plugins.workflow:workflow-support |
|