VDB
CVE-2019-10431
CVE-2019-10431
PUBLISHED
CVSS 6.5 MEDIUM
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
EPSS 0.34% · 57.1th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
0.34%
57.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins project | Jenkins Script Security Plugin | 1.64 and earlier |
| jenkins | script_security | 0 |
| Maven | org.jenkins-ci.plugins:script-security | 0 |
Exploit Intelligence
Timeline
- Oct 1, 2019 CVE Published
- Oct 9, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579 url
- [oss-security] 20191001 Multiple vulnerabilities in Jenkins plugins mailing-list
- RHSA-2019:4097 vendor-advisory
- RHSA-2019:4055 vendor-advisory
- RHSA-2019:4089 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10431 advisory
- https://github.com/jenkinsci/script-security-plugin/commit/415b6e2f3fa0c2e4bd2f9c4a589a9e1fc9cbac8b url
- https://github.com/jenkinsci/script-security-plugin package
- https://github.com/jenkinsci/script-security-plugin/blob/7bd58b8635709cecdb50018844e5d6dbe1ce13ea/CHANGELOG.md url