CVE-2017-1000107
published 2017-10-05CVE-2017-1000107: Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method…
PriorityP343high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.20%
64.8th percentile
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | datadog_plugin | — | — |
| jenkins | deploy_to_container_plugin | — | — |
| jenkins | dry_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | owasp_dependency-check_plugin | — | — |
| jenkins | script_security | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | static_analysis_utilities_plugin | — | — |
| jenkins | warnings_plugin | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
vendor_redhat·2017-08-07·CVSS 8.8
CVE-2017-1000107 [HIGH] CWE-184 jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
Statement: This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat OpenShift Enterprise. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: jenkins-plug
Jenkins
Jenkins Security Advisory 2017-08-07
vendor_jenkins·2017-08-07·CVSS 5.4
CVE-2017-1000102 [MEDIUM] Jenkins Security Advisory 2017-08-07
Title: Jenkins Security Advisory 2017-08-07
Jenkins Security Advisory 2017-08-07
This advisory announces vulnerabilities in these Jenkins plugins:
Blue Ocean
Config File Provider Plugin
Datadog Plugin
Deploy to container Plugin
DRY Plugin
OWASP Dependency-Check Plugin
Pipeline: Groovy Plugin
Pipeline: Input Step Plugin
Script Security Plugin
Static Analysis Utilities Plugin
Description
Persistent XSS vulnerability in Static Analysis Utilities and DRY Plugins
SECURITY-467 / CVE-2017-1000102 (Static Analysis Utilities Plugin) / CVE-2017-1000103 (DRY Plugin)
The "Details" view of Static Analysis Utilities based plugins, as well as the custom "Details" view of the DRY Plugin, was vulnerable to a persisted cross-site
OSV
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
osv·2022-05-13
CVE-2017-1000107 [HIGH] Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
GHSA
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
ghsa·2022-05-13
CVE-2017-1000107 [HIGH] Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
Sandbox bypass in Jenkins Script Security Plugin sandbox bypass
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000107 jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
bugzilla·2017-08-16·CVSS 8.8
CVE-2017-1000107 [HIGH] CVE-2017-1000107 jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
CVE-2017-1000107 jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass
Script Security Plugin did not apply sandbox restrictions to various types of expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
External References:
https://jenkins.io/security/advisory/2017-08-07/
Discussion:
Created jenkins-script-security-plugin tracking bugs for this issue:
Affects: fedora-all [bug 1482093]
---
Statement:
Deferred (Low security impact)
This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat OpenShift Enterprise. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional info
Bugzilla
CVE-2017-1000107 jenkins-script-security-plugin: jenkins-plugin-script-security, jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass [fedora-al
bugzilla·2017-08-16·CVSS 8.8
CVE-2017-1000107 [HIGH] CVE-2017-1000107 jenkins-script-security-plugin: jenkins-plugin-script-security, jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass [fedora-al
CVE-2017-1000107 jenkins-script-security-plugin: jenkins-plugin-script-security, jenkins-plugin-workflow-cps: Multiple Groovy language features allowed Script Security Plugin sandbox bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the
2017-10-05
Published