CVE-2017-1000505
published 2018-01-25CVE-2017-1000505: In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.99%
58.7th percentile
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | script_security | <= 1.36 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
osv·2022-05-14
CVE-2017-1000505 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
ghsa·2022-05-14
CVE-2017-1000505 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.
Jenkins
Jenkins Security Advisory 2017-12-11
vendor_jenkins·2017-12-11·CVSS 6.5
CVE-2017-1000505 [MEDIUM] Jenkins Security Advisory 2017-12-11
Title: Jenkins Security Advisory 2017-12-11
Jenkins Security Advisory 2017-12-11
This advisory announces a vulnerability in this Jenkins plugin:
Script Security
Description
Arbitrary file read vulnerability in Script Security Plugin
SECURITY-663 / CVE-2017-1000505
Users with the ability to configure sandboxed Groovy and Pipeline scripts, including those from SCM, are able to use a type coercion feature in Groovy to create new File objects from strings. This allowed reading arbitrary files on the Jenkins controller file system.
Such a type coercion is now subject to sandbox protection and considered to be a call to the new File(String) constructor for the purpose of in-process script approval.
Severity
SECURITY-663: medium
Affe
Red Hat
jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
vendor_redhat·2017-12-11·CVSS 6.5
CVE-2017-1000505 [MEDIUM] CWE-200 jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.
Statement: This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat Enterprise OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having security impact of Moderate. A future upda
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000505 jenkins-script-security-plugin: jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663) [fedora-all]
bugzilla·2017-12-12·CVSS 6.5
CVE-2017-1000505 [MEDIUM] CVE-2017-1000505 jenkins-script-security-plugin: jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663) [fedora-all]
CVE-2017-1000505 jenkins-script-security-plugin: jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM cha
Bugzilla
CVE-2017-1000505 jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
bugzilla·2017-12-12·CVSS 6.5
CVE-2017-1000505 [MEDIUM] CVE-2017-1000505 jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
CVE-2017-1000505 jenkins-plugin-script-security: Arbitrary file read vulnerability in Script Security Plugin (SECURITY-663)
Users with the ability to configure sandboxed Groovy and Pipeline scripts, including those from SCM, are able to use a type coercion feature in Groovy to create new File objects from strings. This allowed reading arbitrary files on the Jenkins master file system.
Affected versions: Script Security Plugin up to and including 1.36
External References:
https://jenkins.io/security/advisory/2017-12-11/
Discussion:
Created jenkins-script-security-plugin tracking bugs for this issue:
Affects: fedora-all [bug 1524946]
---
Statement:
This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat Enterprise OpenShift Enterprise 3. Red Hat Pr
2018-01-25
Published