Clickjacking in Jenkins and Jenkins LTS - CVE-2020-2105

 

Clickjacking in Jenkins and Jenkins LTS - CVE-2020-2105

Published: January 30, 2020


Vulnerability identifier: #VU24764
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2105
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a clickjacking attack

The vulnerability exists due to the affected software does not serve the "X-Frame-Options: deny" HTTP header on REST API responses to protect against clickjacking attacks. A remote attacker can rout the victim through a specially crafted web page that embeds a REST API endpoint in an iframe and trick the user to perform an action which would allow for the attacker to learn the content of that REST API endpoint.


Affected software

Jenkins
Jenkins LTS
skopeo (Red Hat package)
runc (Red Hat package)
buildah (Red Hat package)
cri-o (Red Hat package)
cri-tools (Red Hat package)
ovn2.12 (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-2105

Install updates from vendor's website.

Jenkins - update to 2.219
Jenkins LTS - update to 2.204.2
skopeo (Red Hat package) - update to 0.1.40-4.rhaos.el8
runc (Red Hat package) - update to 1.0.0-65.rc10.rhaos4.3.el8
buildah (Red Hat package) - update to 1.11.6-4.el8
cri-o (Red Hat package) - update to 1.16.3-22.dev.rhaos4.3.git11c04e3.el8
cri-tools (Red Hat package) - addressed in versions 1.17.0-1.el7, 1.17.0-2.el8
ovn2.12 (Red Hat package) - update to 2.12.0-32.el7fdn
jenkins (Red Hat package) - update to 2.204.2.1583446818-1.el7
Red Hat OpenShift Container Platform - update to 4.3.5
openshift (Red Hat package) - addressed in versions 4.3.5-202002280657.git.0.b3bfb5a.el7, 4.3.5-202002280657.git.0.b3bfb5a.el8
openshift-ansible (Red Hat package) - update to 4.3.5-202002280657.git.1.e4f02b3.el7
openshift-clients (Red Hat package) - addressed in versions 4.3.5-202002280657.git.1.55a9334.el7, 4.3.5-202002280657.git.1.55a9334.el8
atomic-enterprise-service-catalog (Red Hat package) - update to 4.3.5-202003020117.git.0.4eb885c.el7
machine-config-daemon (Red Hat package) - update to 4.3.5-202003020117.git.0.61e0e48.el8
openshift-kuryr (Red Hat package) - update to 4.3.5-202003020117.git.0.237579a.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.3.5-202003020117.git.13.3ac2b0e.el7
jenkins-2-plugins (Red Hat package) - update to 4.3.1583445947-1.el7

External References

Related Security Bulletins