CVE-2019-1003034
08.03.2019, 21:29
A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScriptLoader.groovy, job-dsl-plugin/build.gradle, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/JobDslWhitelist.groovy, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/SandboxDslScriptLoader.groovy that allows attackers with control over Job DSL definitions to execute arbitrary code on the Jenkins master JVM.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | job_dsl | 𝑥 ≤ 1.71 |
redhat | openshift_container_platform | 3.11 |
𝑥
= Vulnerable software versions
References