CVE-2017-1000107Incomplete List of Disallowed Inputs in Jenkins Script Security

Severity
8.8HIGHNVD
EPSS
0.3%
top 49.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 13

Description

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
OSV
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass2022-05-13
GHSA
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass2022-05-13
CVEList
CVE-2017-1000107: Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations,2017-10-04

📋Vendor Advisories

2
Red Hat
jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass2017-08-07
Jenkins
Jenkins Security Advisory 2017-08-072017-08-07

💬Community

2
Bugzilla
CVE-2017-1000107 jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass2017-08-16
Bugzilla
CVE-2017-1000107 jenkins-script-security-plugin: jenkins-plugin-script-security, jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass [fedora-al2017-08-16
CVE-2017-1000107 — Incomplete List of Disallowed Inputs | cvebase