CVE-2017-1000095
published 2017-10-05CVE-2017-1000095: The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String)…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.1th percentile
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild. Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security: groovy.json.JsonOutput.toJson(Closure); groovy.json.JsonOutput.toJson(Object).
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_step_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | github_branch_source_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | ids_in_docker_commons_plugin | — | — |
| jenkins | ids_in_github_branch_source_plugin | — | — |
| jenkins | parameterized_trigger_plugin | — | — |
| jenkins | periodic_backup_plugin | — | — |
| jenkins | plugins_like_authorize_project_plugin | — | — |
| jenkins | poll_scm_plugin | — | — |
| jenkins | role-based_authorization_strategy_plugin | — | — |
| jenkins | script_security | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | sidebar_link_plugin | — | — |
| jenkins | ssh_plugin | — | — |
| jenkins | subversion_plugin | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
ghsa·2022-05-13
CVE-2017-1000095 [MEDIUM] CWE-732 Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild. Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security: groovy.json.JsonOutput.toJson(Closure); groovy.json.JsonOutput.toJson(Object).
OSV
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
osv·2022-05-13
CVE-2017-1000095 [MEDIUM] Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
Unsafe methods in the default list of approved signatures in Jenkins Script Security Plugin
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild. Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security: groovy.json.JsonOutput.toJson(Closure); groovy.json.JsonOutput.toJson(Object).
Red Hat
jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
vendor_redhat·2017-07-10·CVSS 6.5
CVE-2017-1000095 [MEDIUM] CWE-184 jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild. Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security: groovy.json.JsonOutput.toJson(Closure); groovy.json.JsonOutput.toJson(Object).
The jenkins-plugin-script-security improperly whitelisted "DefaultGroovyMethods.putAt(Object, String, Object)" and "DefaultGroovyMethods.getAt(Object, String)" which allows atta
Jenkins
Jenkins Security Advisory 2017-07-10
vendor_jenkins·2017-07-10·CVSS 6.5
CVE-2017-1000084 [MEDIUM] Jenkins Security Advisory 2017-07-10
Title: Jenkins Security Advisory 2017-07-10
Jenkins Security Advisory 2017-07-10
This advisory originally recommended upgrading Poll SCM plugin to version 1.4. This was incorrect. Version 1.3.1 contains the fix.
This advisory announces vulnerabilities in these Jenkins plugins:
Docker Commons Plugin
Git Plugin
GitHub Branch Source Plugin
Parameterized Trigger Plugin
Periodic Backup Plugin
Pipeline: Build Step Plugin
Pipeline: Groovy Plugin
Poll SCM Plugin
Role-based Authorization Strategy Plugin
Script Security Plugin
Sidebar Link Plugin
SSH Plugin
Subversion Plugin
Description
Parameterized Trigger Plugin fails to check Item/Build permission
SECURITY-201 / CVE-2017-1000084
Builds in Jenkins are a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000095 jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
bugzilla·2017-07-14·CVSS 6.5
CVE-2017-1000095 [MEDIUM] CVE-2017-1000095 jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
CVE-2017-1000095 jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538)
The default whitelist included the entries:
DefaultGroovyMethods.putAt(Object, String, Object)
DefaultGroovyMethods.getAt(Object, String)
These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild.
Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security:
groovy.json.JsonOutput.toJson(Closure)
groovy.json.JsonOutput.toJson(Object)
External References:
https://jenkins.io/security/advisory/2017-07-10/
Discussion:
Acknowledgments:
Name: the Jenkins project
---
Created jenkins-script-security-plugin tra
Bugzilla
CVE-2017-1000095 jenkins-script-security-plugin: jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538) [fedora-all]
bugzilla·2017-07-14·CVSS 6.5
CVE-2017-1000095 [MEDIUM] CVE-2017-1000095 jenkins-script-security-plugin: jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538) [fedora-all]
CVE-2017-1000095 jenkins-script-security-plugin: jenkins-plugin-script-security: Unsafe methods in the default whitelist (SECURITY-538) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
2017-10-05
Published