PT-2019-11776 · Jenkins · Jenkins Simple Travis Pipeline Runner Plugin+1

Jesse Glick

·

Published

2019-08-07

·

Updated

2023-10-25

·

CVE-2019-10380

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Simple Travis Pipeline Runner Plugin versions 1.0 and earlier
Description The issue allows attackers to execute arbitrary code by bypassing the Script Security sandbox protection. This is due to the plugin specifying unsafe values in its custom Script Security whitelist. The custom list of pre-approved signatures for scripts protected by the Script Security sandbox enables the use of methods that can bypass protection, resulting in arbitrary code execution on any Jenkins instance with this plugin installed.
Recommendations For Jenkins Simple Travis Pipeline Runner Plugin versions 1.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2019-10380
GHSA-X7P9-VX6V-WV84

Affected Products

Jenkins
Jenkins Simple Travis Pipeline Runner Plugin