CVE-2019-10328

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10328
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10328.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-10328
Aliases
Related
Published
2019-05-31T15:29:00Z
Modified
2024-10-12T04:13:42.986020Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

References

Affected packages

Git / github.com/jenkinsci/workflow-remote-loader-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/workflow-remote-loader-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

workflow-remote-loader-1.*

workflow-remote-loader-1.0
workflow-remote-loader-1.1
workflow-remote-loader-1.2
workflow-remote-loader-1.3
workflow-remote-loader-1.4