PT-2019-11776 · Jenkins · Jenkins Simple Travis Pipeline Runner Plugin+1
Jesse Glick
·
Published
2019-08-07
·
Updated
2023-10-25
·
CVE-2019-10380
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Simple Travis Pipeline Runner Plugin versions 1.0 and earlier
Description
The issue allows attackers to execute arbitrary code by bypassing the Script Security sandbox protection. This is due to the plugin specifying unsafe values in its custom Script Security whitelist. The custom list of pre-approved signatures for scripts protected by the Script Security sandbox enables the use of methods that can bypass protection, resulting in arbitrary code execution on any Jenkins instance with this plugin installed.
Recommendations
For Jenkins Simple Travis Pipeline Runner Plugin versions 1.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Simple Travis Pipeline Runner Plugin