CVE-2019-10418
Description
Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
CWE
- (none)
Affected
- Jenkins project / Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin — v=1.6 and earlier [affected]
CVSS
- (none)
References
- https://jenkins.io/security/advisory/2019-09-25/#SECURITY-920%20%282%29 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2019/09/25/3 mailing-list, x_refsource_MLIST
Source
cvelistV5-main/cves/2019/10xxx/CVE-2019-10418.json