CVE-2019-10393: Medium severity jenkins script security vulnerability
Published Sep 12, 2019
·Updated
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:script-security<=1.62
1.63
Jenkins Script Security Jenkins<=1.62
Event History
Sep 12, 2019
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
May 24, 2022
Advisory Published
04:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10393?
CVE-2019-10393 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2019-10393?
To fix CVE-2019-10393, upgrade the Jenkins Script Security Plugin to version 1.63 or later.
3
What systems are affected by CVE-2019-10393?
CVE-2019-10393 affects Jenkins Script Security Plugin versions 1.62 and earlier.
4
Can CVE-2019-10393 be exploited remotely?
Yes, CVE-2019-10393 can be exploited remotely, allowing attackers to execute arbitrary code.
5
Is there a workaround for CVE-2019-10393?
There are no known workarounds for CVE-2019-10393; the recommended action is to update the plugin.