CVE-2019-10328

Aliases:GHSA-v558-fhw2-v46w
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 31 May 2019, 14:20
Last modified:04 Aug 2024, 22:17

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.9 CRITICAL
v3.0 (nvd)
EPSS Score
0.27% LOW
0% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

31 May 2019, 14:20
Published
Vulnerability first disclosed
04 Aug 2024, 22:17
Last Modified
Vulnerability information updated

Description

Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

CVSS Metrics

  • v3.0CRITICALScore: 9.9CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.5AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.27% Percentile: 50%

Techniques & Countermeasures

  • CWE-693Protection Mechanism Failure

    The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Systems

  • jenkins projectjenkins pipeline remote loader plugin

    1.4 and earlier

  • jenkinspipeline_remote_loader

    ≤ 1.4

  • org.jenkins-ci.pluginsworkflow-remote-loader

    < 1.5

References (8)