[JENKINS:SECURITY-1737] RCE vulnerability in `DotCi`

Severity High
Affected Packages 2
CVEs 1

DotCi 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types.

This results in a remote code execution (RCE) vulnerability exploitable by attackers able to modify .ci.yml files in SCM.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-1737
Severity
high
Published
2022-09-21T00:00:00
(2 years ago)
Modified
2022-09-21T00:00:00
(2 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository DotCi repository https://github.com/jenkinsci/DotCi-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/DotCi org.jenkins-ci.plugins DotCi <= 2.40.00
Affected pkg:github/jenkinsci/dotci-plugin jenkinsci dotci-plugin <= 2.40.00
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...