CVE-2019-1003011 PUBLISHED

Reported by jenkins · Published February 6, 2019

An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/AbstractChangesSinceMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/ChangesSinceLastBuildMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/ProjectUrlMacro.java that allows attackers with the ability to control token macro input (such as SCM changelogs) to define recursive input that results in unexpected macro evaluation.

Affected Products

VendorProductVersions
Jenkins projectJenkins Token Macro Plugin2.5 and earlier
Mavenorg.jenkins-ci.plugins:token-macro0, 0
Jenkins projectJenkins Token Macro Plugin2.5 and earlier, 2.5 and earlier

Timeline

References

Open in Interactive Console →