Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2019/08/07/1 | Mailing List Third Party Advisory |
https://jenkins.io/security/advisory/2019-08-07/#SECURITY-922 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2019-08-07T14:20:24
Updated: 2023-10-24T16:48:30.137Z
Reserved: 2019-03-29T00:00:00
Link: CVE-2019-10380
JSON object: View
NVD Information
Status : Modified
Published: 2019-08-07T15:15:13.283
Modified: 2023-10-25T18:16:19.577
Link: CVE-2019-10380
JSON object: View
Redhat Information
No data.
CWE