VDB
CVE-2019-10431
CVE-2019-10431
PUBLISHED
CVSS 6.5 MEDIUM
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
EPSS 2.70% · 84.5th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
2.70%
84.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins project | Jenkins Script Security Plugin | 1.64 and earlier |
| jenkins | script_security | 0 |
| Maven | org.jenkins-ci.plugins:script-security | 0 |
Timeline
- Oct 1, 2019 CVE Published
- Oct 9, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
References
- [oss-security] 20191001 Multiple vulnerabilities in Jenkins plugins mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2019-10431 advisory
- https://github.com/jenkinsci/script-security-plugin/commit/415b6e2f3fa0c2e4bd2f9c4a589a9e1fc9cbac8b url
- https://github.com/jenkinsci/script-security-plugin package
- https://github.com/jenkinsci/script-security-plugin/blob/7bd58b8635709cecdb50018844e5d6dbe1ce13ea/CHANGELOG.md url
- https://access.redhat.com/errata/RHSA-2019:4055 technical
- https://access.redhat.com/errata/RHSA-2019:4097 technical
- https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579 advisory
- https://access.redhat.com/errata/RHSA-2019:4089 technical