Remote Code Execution Vulnerability in Jenkins Pipeline Plugin
CVE-2019-10328

9.9CRITICAL

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
31 May 2019

What is CVE-2019-10328?

The Jenkins Pipeline Remote Loader Plugin versions 1.4 and earlier have a vulnerability that allows attackers to invoke arbitrary methods. This weakness undermines the effectiveness of the plugin's custom whitelist for script security, enabling the circumvention of the standard sandbox protections that should safeguard the execution of scripts. Consequently, unauthorized access and control over the Jenkins server may be possible, posing a significant risk to the integrity and security of the continuous integration process.

Affected Version(s)

Jenkins Pipeline Remote Loader Plugin 1.4 and earlier

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.