Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HJenkins Official Owasp Zap
APPJenkins≤ 1.0.7
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCECI/CD
CWE
Powiązane podatności
CVE-2019-1003060HIGH8.8ten sam produkt
Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenki...
CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓ten sam vendor
Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam vendor
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam vendor
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework