CVE-2017-1000107: High severity jenkins script security vulnerability
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000107?
CVE-2017-1000107 is considered a medium severity vulnerability that can lead to arbitrary code execution.
How do I fix CVE-2017-1000107?
To address CVE-2017-1000107, upgrade Jenkins Script Security Plugin to version 1.31 or later.
What is the impact of CVE-2017-1000107?
CVE-2017-1000107 allows attackers to bypass sandbox protection and invoke arbitrary constructors and methods.
Which versions of Jenkins are affected by CVE-2017-1000107?
Jenkins Script Security Plugin version 1.30 is affected by CVE-2017-1000107.
Is there a workaround for CVE-2017-1000107?
There is no official workaround for CVE-2017-1000107; the recommended action is to upgrade to a secure version.