cbcvebase.
CVE-2019-16538
published 2019-11-21

CVE-2019-16538: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed…

PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.43%
70.0th percentile
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsanchore_container_image_scanner_plugin
jenkinsfolder-scoped_jira_sites_in_jira_plugin
jenkinsgoogle_compute_engine_plugin
jenkinsjira_plugin
jenkinsqmetry_for_jira_test_management_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security<= 1.67
jenkinsscript_security_plugin
jenkinsspira_importer_plugin
jenkinssupport_core_plugin
jenkinsvms_launched_by_the_plugin
jenkins_projectjenkins_script_security_plugin

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.