Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
References
Configurations
History
No history.
Information
Published : 2019-05-31 15:29
Updated : 2023-10-25 18:16
NVD link : CVE-2019-10328
Mitre link : CVE-2019-10328
CVE.ORG link : CVE-2019-10328
JSON object : View
Products Affected
jenkins
- pipeline_remote_loader
CWE
CWE-693
Protection Mechanism Failure