CVE-2019-10431: Code Injection
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
Other sources
Sandbox protection in Script Security Plugin could be circumvented through default parameter expressions in constructors. This allowed attackers able to specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.
References:
https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10431?
CVE-2019-10431 is rated as a high severity vulnerability due to its potential for arbitrary code execution within sandboxed scripts.
How do I fix CVE-2019-10431?
To fix CVE-2019-10431, upgrade the Jenkins Script Security Plugin to version 1.65 or later.
What systems are affected by CVE-2019-10431?
CVE-2019-10431 affects Jenkins Script Security Plugin versions up to and including 1.64.
What type of vulnerability is CVE-2019-10431?
CVE-2019-10431 is a sandbox bypass vulnerability that allows attackers to execute arbitrary code.
Which plugin needs to be updated for CVE-2019-10431?
The Jenkins Script Security Plugin needs to be updated to address CVE-2019-10431.