Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade rubygem-faradayUpgrade rubygem-fluent-plugin-viaq_data_modelUpgrade fluentdUpgrade rubygem-exconUpgrade rubygem-i18nUpgrade jenkins-2-pluginsUpgrade rubygem-cool.ioUpgrade kibanaUpgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade atomic-openshiftUpgrade rubygem-systemd-journal | May 7, 2019 | Jul 10, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub