cbcvebase.
CVE-2019-10355
published 2019-07-31

CVE-2019-10355: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsamazon_ec2_plugin
jenkinsbetween_configuration_as_code_plugin
jenkinsconfiguration_as_code_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsgoogle_kubernetes_engine_plugin
jenkinsmaven_integration_plugin
jenkinsmaven_release_plug-in_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security<= 1.61
jenkinsscript_security_plugin
jenkinssince_configuration_as_code_plugin
jenkinsskytap_cloud_ci_plugin
jenkins_projectjenkins_script_security_plugin
redhatopenshift_container_platform
redhatopenshift_container_platform