SB2019041116 - Arch Linux update for jenkins



SB2019041116 - Arch Linux update for jenkins

Published: April 11, 2019 Updated: April 11, 2019

Security Bulletin ID SB2019041116
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2019-1003049)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.


2) Cross-site scripting (CVE-ID: CVE-2019-1003050)

The vulnerability allows a remote authenticated user to read and manipulate data.

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.


Remediation

Install update from vendor's website.