CVE-2019-10417: Critical severity jenkins kubernetes pipeline vulnerability
Published Sep 25, 2019
·Updated
Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
Affected Software
2 affected components
maven/io.fabric8.pipeline:kubernetes-pipeline-steps<=1.6
Jenkins Kubernetes Pipeline Jenkins<=1.6
Event History
Sep 25, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
May 24, 2022
Advisory Published
04:56 PM
Frequently Asked Questions
1
Is a fix mandatory for CVE-2019-10417?
Yes, applying the fix for CVE-2019-10417 is recommended to secure your Jenkins environment.