CVE-2019-10306: Critical severity jenkins vulnerability
Published Apr 18, 2019
·Updated
A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:ontrack<3.4.1
3.4.1
Jenkins ontrack Jenkins<=3.4
Event History
Apr 18, 2019
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
May 24, 2022
Advisory Published
04:43 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10306?
CVE-2019-10306 has a high severity rating due to its potential to allow execution of arbitrary code on the Jenkins master JVM.
2
How do I fix CVE-2019-10306?
To fix CVE-2019-10306, upgrade the Jenkins ontrack Plugin to version 3.4.1 or later.
3
What software is affected by CVE-2019-10306?
CVE-2019-10306 affects Jenkins ontrack Plugin versions 3.4 and earlier.
4
What type of vulnerability is CVE-2019-10306?
CVE-2019-10306 is a sandbox bypass vulnerability that allows for arbitrary code execution.
5
Who is primarily affected by CVE-2019-10306?
Users of the Jenkins ontrack Plugin who allow control over ontrack DSL definitions are primarily affected by CVE-2019-10306.