CVE-2019-10328: Critical severity jenkins pipeline remote loader vulnerability

Published May 31, 2019
·
Updated

A flaw was found in the Jenkins Workflow Remote Loader plugin. An unsafe whitelist entry was made that allowed invoking arbitrary methods and bypassing sandbox protection. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Other sources

Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

Jenkins Pipeline Remote Loader Plugin before 1.5 provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

The Jenkins Pipeline Remote Loader Plugin provides a custom Script Security whitelist. Those entries apply to all scripts with sandbox protection, such as Pipeline.

One entry provided here was unsafe, as it allowed invoking arbitrary methods, bypassing sandbox protection.

The unsafe whitelist entry has been removed.

External References:

https://jenkins.io/security/advisory/2019-05-31/#SECURITY-921

Red Hat

Affected Software

22 affected componentsFixes available
redhat/atomic-enterprise-service-catalog<1:3.11.117-1.git.1.376e432.el7
1:3.11.117-1.git.1.376e432.el7
redhat/atomic-openshift-cluster-autoscaler<0:3.11.117-1.git.1.caa79fa.el7
0:3.11.117-1.git.1.caa79fa.el7
redhat/atomic-openshift-descheduler<0:3.11.117-1.git.1.1635b0a.el7
0:3.11.117-1.git.1.1635b0a.el7
redhat/atomic-openshift-dockerregistry<0:3.11.117-1.git.1.6a42b08.el7
0:3.11.117-1.git.1.6a42b08.el7
redhat/atomic-openshift-metrics-server<0:3.11.117-1.git.1.319d58e.el7
0:3.11.117-1.git.1.319d58e.el7
redhat/atomic-openshift-node-problem-detector<0:3.11.117-1.git.1.0345fe3.el7
0:3.11.117-1.git.1.0345fe3.el7
redhat/atomic-openshift-service-idler<0:3.11.117-1.git.1.887bb82.el7
0:3.11.117-1.git.1.887bb82.el7
redhat/atomic-openshift-web-console<0:3.11.117-1.git.1.be7a05c.el7
0:3.11.117-1.git.1.be7a05c.el7
redhat/cri-o<0:1.11.14-1.rhaos3.11.gitd56660e.el7
0:1.11.14-1.rhaos3.11.gitd56660e.el7
redhat/golang-github-openshift-oauth-proxy<0:3.11.117-1.git.1.2b006d2.el7
0:3.11.117-1.git.1.2b006d2.el7
redhat/golang-github-prometheus-alertmanager<0:3.11.117-1.git.1.207ef35.el7
0:3.11.117-1.git.1.207ef35.el7
redhat/golang-github-prometheus-prometheus<0:3.11.117-1.git.1.f52d417.el7
0:3.11.117-1.git.1.f52d417.el7
redhat/jenkins<0:2.164.2.1555422716-1.el7
0:2.164.2.1555422716-1.el7
redhat/jenkins<2-plugins-0:3.11.1559667994-1.el7
2-plugins-0:3.11.1559667994-1.el7
redhat/openshift-ansible<0:3.11.123-1.git.0.db681ba.el7
0:3.11.123-1.git.0.db681ba.el7
redhat/openshift-enterprise-autoheal<0:3.11.117-1.git.1.ef32a58.el7
0:3.11.117-1.git.1.ef32a58.el7
redhat/openshift-enterprise-cluster-capacity<0:3.11.117-1.git.1.6593fce.el7
0:3.11.117-1.git.1.6593fce.el7
redhat/jenkins<2-plugins-0:4.1.1561471763-1.el7
2-plugins-0:4.1.1561471763-1.el7
redhat/jenkins<2-plugins-0:4.2.1568997376-1.el7
2-plugins-0:4.2.1568997376-1.el7
Jenkins Pipeline Remote Loader Jenkins<=1.4
maven/org.jenkins-ci.plugins:workflow-remote-loader<1.5
1.5
redhat/jenkins-plugin-workflow-remote-loader<1.5
1.5

Event History

May 31, 2019
CVE Published
12:00 AM
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
May 24, 2022
Advisory Published
10:00 PM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2019-10328?

CVE-2019-10328 has been classified as having a high severity due to its potential impact on data confidentiality, integrity, and system availability.

2

How do I fix CVE-2019-10328?

To address CVE-2019-10328, update the Jenkins Workflow Remote Loader plugin to version 1.5 or later.

3

What systems are affected by CVE-2019-10328?

CVE-2019-10328 affects Jenkins installations with the Workflow Remote Loader plugin prior to version 1.5.

4

What type of vulnerability is CVE-2019-10328?

CVE-2019-10328 is a security vulnerability that allows arbitrary method invocation and bypasses sandbox protections in Jenkins.

5

Is CVE-2019-10328 related to Jenkins security risks?

Yes, CVE-2019-10328 poses significant security risks to Jenkins users by threatening the confidentiality and integrity of their data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203