Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 646008 (CVE-2017-1000391, CVE-2017-1000392, CVE-2017-1000503, CVE-2017-1000504) - <dev-util/jenkins-bin-2.95: Multiple vulnerabilities
Summary: <dev-util/jenkins-bin-2.95: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-1000391, CVE-2017-1000392, CVE-2017-1000503, CVE-2017-1000504
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa cve]
Keywords:
: 641104 (view as bug list)
Depends on:
Blocks:
 
Reported: 2018-01-29 00:05 UTC by GLSAMaker/CVETool Bot
Modified: 2018-11-24 23:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2018-01-29 00:05:05 UTC
CVE-2017-1000504 (https://nvd.nist.gov/vuln/detail/CVE-2017-1000504):
  A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup
  could result in the wrong order of execution of commands during
  initialization. There is a very short window of time after startup during
  which Jenkins may no longer show the 'Please wait while Jenkins is getting
  ready to work' message but Cross-Site Request Forgery (CSRF) protection may
  not yet be effective.

CVE-2017-1000503 (https://nvd.nist.gov/vuln/detail/CVE-2017-1000503):
  A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1
  startup could result in the wrong order of execution of commands during
  initialization. This could in rare cases result in failure to initialize the
  setup wizard on the first startup. This resulted in multiple
  security-related settings not being set to their usual strict default.

CVE-2017-1000392 (https://nvd.nist.gov/vuln/detail/CVE-2017-1000392):
  Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for
  text fields were not escaped, resulting in a persisted cross-site scripting
  vulnerability if the source for the suggestions allowed specifying text that
  includes HTML metacharacters like less-than and greater-than characters.

CVE-2017-1000391 (https://nvd.nist.gov/vuln/detail/CVE-2017-1000391):
  Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata
  related to 'people', which encompasses actual user accounts, as well as
  users appearing in SCM, in directories corresponding to the user ID on disk.
  These directories used the user ID for their name without additional
  escaping, potentially resulting in problems like overwriting of unrelated
  configuration files.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-02-21 23:21:38 UTC
*** Bug 641104 has been marked as a duplicate of this bug. ***
Comment 2 Hans de Graaff gentoo-dev Security 2018-02-26 18:48:02 UTC
Vulnerable versions have been removed.