[JENKINS:SECURITY-440] Arbitrary file read vulnerability in SSH Credentials Plugin with Credentials Binding Plugin

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

SSH Credentials Plugin allowed the creation of SSH credentials with keys "From a file on Jenkins controller".
Credentials Binding Plugin 1.13 and newer allows binding SSH credentials to environment variables.
In combination, these two features allow users with the permission to configure a job to read arbitrary files on the Jenkins controller by creating an SSH credential referencing an arbitrary file on the Jenkins controller, and binding it to an environment variable in a job.

SSH Credentials Plugin no longer supports SSH credentials from files on the Jenkins controller file system, neither user-specified file paths nor ~/.ssh.
Existing SSH credentials of these kinds are migrated to "directly entered" SSH credentials.

NOTE: If plugin:blueocean[Blue Ocean] is installed, it needs to be updated to 1.5.1 or 1.6.1, or the creation of pipelines for plain Git will not work anymore after installing the fix for this issue.

ID
JENKINS:SECURITY-440
Severity
medium
Published
2018-06-25T00:00:00
(6 years ago)
Modified
2018-06-25T00:00:00
(6 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository ssh-credentials repository https://github.com/jenkinsci/ssh-credentials-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/ssh-credentials org.jenkins-ci.plugins ssh-credentials <= 1.13
Fixed pkg:maven/org.jenkins-ci.plugins/ssh-credentials org.jenkins-ci.plugins ssh-credentials = 1.14
Affected pkg:github/jenkinsci/ssh-credentials-plugin jenkinsci ssh-credentials-plugin <= 1.13
Fixed pkg:github/jenkinsci/ssh-credentials-plugin jenkinsci ssh-credentials-plugin = 1.14
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...