1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: Jenkins Metaprogramming RCE Activity

Attack: Jenkins Metaprogramming RCE Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects the attempt to bypass certain security restrictions to perform unauthorized actions or to execute arbitrary code within the context of the application.

Additional Information

Jenkins is prone to the following security-bypass vulnerabilities:

1. A security-bypass vulnerability exists in Script Security plugin. Specifically, this issue affects the 'src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java' source file. An attacker can exploit this issue by using a sandbox script to execute arbitrary code in Jenkins master JVM. [CVE-2019-1003000]

2. Multiple security-bypass vulnerability exist in Pipeline: Groovy plugin. Specifically, these issues affect the 'src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java' and 'src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java' source files. An attacker can exploit these issues by using a pipeline script to execute arbitrary code in Jenkins master JVM. [CVE-2019-1003001]

3. A security-bypass vulnerability exists in Pipeline: Declarative Plugin. Specifically, this issue affects the 'pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy' source file. An attacker can exploit this issue by using a pipeline script to execute arbitrary code in Jenkins master JVM. [CVE-2019-1003000]

Attackers can exploit these issues to bypass certain security restrictions to perform unauthorized actions or to execute arbitrary code within the context of the application.

Affected

  • The following versions of Jenkins are vulnerable:
  • Jenkins Pipeline: Declarative Plugin 1.3.4 and prior.
  • Jenkins Pipeline: Groovy Plugin 2.61 and prior.
  • Jenkins Script Security Plugin 1.49 and prior.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube