Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-918 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2019-10-16T13:00:54
Updated: 2023-10-24T16:50:01.835Z
Reserved: 2019-03-29T00:00:00
Link: CVE-2019-10458
JSON object: View
NVD Information
Status : Modified
Published: 2019-10-16T14:15:13.607
Modified: 2023-10-25T18:16:24.740
Link: CVE-2019-10458
JSON object: View
Redhat Information
No data.
CWE