CVE-2019-4055
published 2019-04-19CVE-2019-4055: IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.49%
82.8th percentile
IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | 8.0.0.0 – 8.0.0.10 | — |
| ibm | mq | 9.0.0.0 – 9.0.0.5 | — |
| ibm | mq | 9.1.0 – 9.1.1 | — |
| ibm | mq | 9.1.0.0 – 9.1.0.1 | — |
| ibm | mq_appliance | 8.0.0.0 – 8.0.0.10 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10393 jenkins-script-security-plugin: handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts
bugzilla·2020-04-01·CVSS 4.2
CVE-2019-10393 [MEDIUM] CVE-2019-10393 jenkins-script-security-plugin: handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts
CVE-2019-10393 jenkins-script-security-plugin: handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Reference:
http://www.openwall.com/lists/oss-security/2019/09/12/2
Discussion:
Created jenkins-script-security-plugin tracking bugs for this issue:
Affects: fedora-30 [bug 1819699]
---
External References:
https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1538
---
Fixed in OpenShift Container Platform 3.11 in the below advisory:
https://access.redhat.com/errata/RHSA-2019:4055
---
Fixed in OpenShif
Bugzilla
CVE-2019-10394 jenkins-script-security-plugin: handling of property names in property expressions on the left-hand side of assignment expression leads to execute arbitrary code in sandboxed scripts
bugzilla·2020-04-01·CVSS 4.2
CVE-2019-10394 [MEDIUM] CVE-2019-10394 jenkins-script-security-plugin: handling of property names in property expressions on the left-hand side of assignment expression leads to execute arbitrary code in sandboxed scripts
CVE-2019-10394 jenkins-script-security-plugin: handling of property names in property expressions on the left-hand side of assignment expression leads to execute arbitrary code in sandboxed scripts
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Reference:
http://www.openwall.com/lists/oss-security/2019/09/12/2
Discussion:
Created jenkins-script-security-plugin tracking bugs for this issue:
Affects: fedora-30 [bug 1819693]
---
Fixed in OpenShift Container Platform 3.11 in the below advisory:
https://access.redhat.com/errata/RHSA-2019:4055
---
External References:
https
http://www.securityfocus.com/bid/108027https://exchange.xforce.ibmcloud.com/vulnerabilities/156564https://www.ibm.com/support/docview.wss?uid=ibm10870484http://www.securityfocus.com/bid/108027https://exchange.xforce.ibmcloud.com/vulnerabilities/156564https://www.ibm.com/support/docview.wss?uid=ibm10870484
2019-04-19
Published