Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
References
Configurations
Information
Published : 2019-05-31 08:29
Updated : 2019-06-03 06:29
NVD link : CVE-2019-10328
Mitre link : CVE-2019-10328
JSON object : View
CWE
CWE-693
Protection Mechanism Failure
Products Affected
jenkins
- pipeline_remote_loader