CVE-2019-10418: Critical severity jenkins kubernetes pipeline vulnerability
Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10418?
CVE-2019-10418 has been rated as a high severity vulnerability due to its ability to bypass security restrictions in Jenkins.
How do I fix CVE-2019-10418?
To fix CVE-2019-10418, update to a version of the Jenkins Kubernetes Pipeline that is greater than 1.6.
What software is affected by CVE-2019-10418?
CVE-2019-10418 affects the Jenkins Kubernetes Pipeline up to version 1.6 and the Kubernetes Pipeline Arquillian Steps Plugin up to version 1.6.
What can attackers do with CVE-2019-10418?
Attackers can invoke arbitrary methods in Jenkins with CVE-2019-10418, effectively bypassing the typical script security sandbox protection.
Is there a workaround for CVE-2019-10418?
Currently, the recommended approach to mitigate CVE-2019-10418 is to update to a secure version as no specific workaround has been provided.