CVE-2016-3721
published 2016-05-17CVE-2016-3721: Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
2.12%
80.0th percentile
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | git_server_plugin | — | — |
| jenkins | jenkins | <= 1.651.1 | — |
| jenkins | jenkins | <= 2.2 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | rather_than_expect_all_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | subversion_partial_release_manager | <= 1.0.1 | — |
| jenkins | subversion_partial_release_manager_plugin | — | — |
| jenkins | telegram_bot_plugin | — | — |
| jenkins_project | jenkins_subversion_partial_release_manager_plugin | <= 1.0.1 | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2024-05-02
vendor_jenkins·2024-05-02·CVSS 9.8
CVE-2016-3721 [CRITICAL] Jenkins Security Advisory 2024-05-02
Title: Jenkins Security Advisory 2024-05-02
Jenkins Security Advisory 2024-05-02
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Git server
Plugin
Script Security
Plugin
Subversion Partial Release Manager
Plugin
Telegram Bot
Plugin
Descriptions
Multiple sandbox bypass vulnerabilities in Script Security
Red Hat
jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
vendor_redhat·2016-05-11·CVSS 4.3
CVE-2016-3721 [MEDIUM] jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Jenkins
Jenkins Security Advisory 2016-05-11
vendor_jenkins·2016-05-11·CVSS 4.3
CVE-2016-3721 [MEDIUM] Jenkins Security Advisory 2016-05-11
Title: Jenkins Security Advisory 2016-05-11
Jenkins Security Advisory 2016-05-11
Revised 2016-05-12 : Added note on plugins impacted by SECURITY-170, mentioned system property disabling part of the SECURITY-243 fix.
This advisory announces multiple vulnerabilities in Jenkins.
Description
Arbitrary build parameters are passed to build scripts as environment variables
SECURITY-170 / CVE-2016-3721
Build parameters in Jenkins typically are passed to build scripts as environment variables. Some plugins allow passing arbitrary (undeclared) parameters. Depending on access permissions and installed plugins, malicious users were able to trigger builds, passing arbitrary environment variables (e.g. PATH) to modify the behavior of those build
GHSA
Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
ghsa·2024-05-02·CVSS 4.3
CVE-2024-34148 [MEDIUM] CWE-1321 Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically sets the Java system property `hudson.model.ParametersAction.keepUndefinedParameters` whenever a build is triggered from a release tag with the 'Svn-Partial Release Manager' SCM. Doing so disables the fix for [SECURITY-170](https://www.jenkins.io/security/advisory/2016-05-11/#arbitrary-build-parameters-are-passed-to-build-scripts-as-environment-variables) / CVE-2016-3721.
As of publication of this advisory, there is no fix.
OSV
Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
osv·2024-05-02·CVSS 4.3
CVE-2024-34148 [MEDIUM] Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically sets the Java system property `hudson.model.ParametersAction.keepUndefinedParameters` whenever a build is triggered from a release tag with the 'Svn-Partial Release Manager' SCM. Doing so disables the fix for [SECURITY-170](https://www.jenkins.io/security/advisory/2016-05-11/#arbitrary-build-parameters-are-passed-to-build-scripts-as-environment-variables) / CVE-2016-3721.
As of publication of this advisory, there is no fix.
GHSA
Jenkins allows Remote Users to Inject Build Parameters
ghsa·2022-05-14
CVE-2016-3721 [MEDIUM] CWE-94 Jenkins allows Remote Users to Inject Build Parameters
Jenkins allows Remote Users to Inject Build Parameters
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
OSV
Jenkins allows Remote Users to Inject Build Parameters
osv·2022-05-14
CVE-2016-3721 [MEDIUM] Jenkins allows Remote Users to Inject Build Parameters
Jenkins allows Remote Users to Inject Build Parameters
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3721 jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3721 [MEDIUM] CVE-2016-3721 jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
CVE-2016-3721 jenkins: Arbitrary build parameters are passed to build scripts as environment variables (SECURITY-170)
The following flaw was found in Jenkins:
Build parameters in Jenkins typically are passed to build scripts as environment variables. Some plugins allow passing arbitrary (undeclared) parameters. Depending on access permissions and installed plugins, malicious users were able to trigger builds, passing arbitrary environment variables (e.g. PATH) to modify the behavior of those builds. Rather than expect all plugin authors to be aware of this potential problem, Jenkins now filters the build parameters based on what is defined on the job.
As this change is known to affect a number of plugins, it's possible to restore the previous behavior by setting the system property huds
Bugzilla
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3721 [MEDIUM] CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttp://www.openwall.com/lists/oss-security/2024/05/02/3https://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttp://www.openwall.com/lists/oss-security/2024/05/02/3https://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
2016-05-17
Published