Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remediate CVE-2022-27204 by removing capability to use arbitrary URL #61

Merged
merged 1 commit into from
Dec 4, 2022
Merged

Remediate CVE-2022-27204 by removing capability to use arbitrary URL #61

merged 1 commit into from
Dec 4, 2022

Conversation

chonton
Copy link
Collaborator

@chonton chonton commented Nov 26, 2022

Remediate CVE-2022-27204 by removing capability to use arbitrary URL to fetch properties.
The propertyFile param can no longer be a URL and must be a file path. The URL capability was not a documented feature.

This remediates CVE-2022-27204 and closes CSRF vulnerability and missing permission checks allow SSRF

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did
  • Link to relevant issues in GitHub or Jira
  • Link to relevant pull requests, esp. upstream and downstream changes

@chonton chonton requested a review from a team as a code owner November 26, 2022 18:14
@chonton
Copy link
Collaborator Author

chonton commented Nov 26, 2022

@daniel-beck Please review

…to fetch properties.

The propertyFile param can no longer be a URL and must be a file path. The URL capability was not a documented feature.
@chonton chonton merged commit 35dcfdd into jenkinsci:master Dec 4, 2022
@chonton chonton deleted the CVE-2022-27204 branch December 31, 2022 01:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant