CVE-2019-10458: Critical severity jenkins vulnerability
Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10458?
CVE-2019-10458 has a medium severity rating, threatening the security of Jenkins installations by allowing arbitrary code execution.
How do I fix CVE-2019-10458?
To fix CVE-2019-10458, upgrade Jenkins Puppet Enterprise Pipeline to version 1.3.2 or later, which addresses the vulnerability.
What are the potential impacts of CVE-2019-10458?
The potential impacts of CVE-2019-10458 include unauthorized access to sensitive data and the ability to execute arbitrary code on the Jenkins server.
Who is affected by CVE-2019-10458?
CVE-2019-10458 affects users of Jenkins Puppet Enterprise Pipeline version 1.3.1 and earlier.
When was CVE-2019-10458 disclosed?
CVE-2019-10458 was disclosed on October 16, 2019.