9.9
CVSSv3

CVE-2019-10328

Published: 31/05/2019 Updated: 25/10/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Jenkins Pipeline Remote Loader Plugin 1.4 and previous versions provided a custom whitelist for script security that allowed malicious users to invoke arbitrary methods, bypassing typical sandbox protection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins pipeline remote loader

Vendor Advisories

Synopsis Important: OpenShift Container Platform 41 jenkins-2-plugins security update Type/Severity Security Advisory: Important Topic An update for jenkins-2-plugins is now available for Red Hat OpenShiftContainer Platform 41Red Hat Product Security has rated this update as having a security impactof Im ...
Impact: Important Public Date: 2019-05-31 CWE: CWE-184 Bugzilla: 1716794: CVE-2019-10328 jenkins-plugin ...