CVE-2019-10394: Medium severity jenkins script security vulnerability
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10394?
CVE-2019-10394 is classified as a medium-severity vulnerability due to its potential to allow arbitrary code execution in sandboxed scripts.
How do I fix CVE-2019-10394?
To mitigate CVE-2019-10394, upgrade Jenkins Script Security Plugin to version 1.63 or later.
What type of vulnerability is CVE-2019-10394?
CVE-2019-10394 is a sandbox bypass vulnerability affecting the Jenkins Script Security Plugin.
Which versions of Jenkins are affected by CVE-2019-10394?
CVE-2019-10394 affects Jenkins Script Security Plugin versions 1.62 and earlier.
What can an attacker do with CVE-2019-10394?
An attacker exploiting CVE-2019-10394 can execute arbitrary code within sandboxed scripts, compromising the affected Jenkins instance.