Remote Code Execution Vulnerability in Jenkins Pipeline Plugin
CVE-2019-10328
9.9CRITICAL
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 31 May 2019
What is CVE-2019-10328?
The Jenkins Pipeline Remote Loader Plugin versions 1.4 and earlier have a vulnerability that allows attackers to invoke arbitrary methods. This weakness undermines the effectiveness of the plugin's custom whitelist for script security, enabling the circumvention of the standard sandbox protections that should safeguard the execution of scripts. Consequently, unauthorized access and control over the Jenkins server may be possible, posing a significant risk to the integrity and security of the continuous integration process.
Affected Version(s)
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier