CVE-2019-10328: Critical severity jenkins pipeline remote loader vulnerability
A flaw was found in the Jenkins Workflow Remote Loader plugin. An unsafe whitelist entry was made that allowed invoking arbitrary methods and bypassing sandbox protection. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
Jenkins Pipeline Remote Loader Plugin before 1.5 provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
The Jenkins Pipeline Remote Loader Plugin provides a custom Script Security whitelist. Those entries apply to all scripts with sandbox protection, such as Pipeline.
One entry provided here was unsafe, as it allowed invoking arbitrary methods, bypassing sandbox protection.
The unsafe whitelist entry has been removed.
External References:
https://jenkins.io/security/advisory/2019-05-31/#SECURITY-921
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-10328?
CVE-2019-10328 has been classified as having a high severity due to its potential impact on data confidentiality, integrity, and system availability.
How do I fix CVE-2019-10328?
To address CVE-2019-10328, update the Jenkins Workflow Remote Loader plugin to version 1.5 or later.
What systems are affected by CVE-2019-10328?
CVE-2019-10328 affects Jenkins installations with the Workflow Remote Loader plugin prior to version 1.5.
What type of vulnerability is CVE-2019-10328?
CVE-2019-10328 is a security vulnerability that allows arbitrary method invocation and bypasses sandbox protections in Jenkins.
Is CVE-2019-10328 related to Jenkins security risks?
Yes, CVE-2019-10328 poses significant security risks to Jenkins users by threatening the confidentiality and integrity of their data.