Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
2019-05-31T15:29:00.513
2024-11-21T04:18:54.057
Modified
CVSSv3.0: 9.9 (CRITICAL)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | pipeline_remote_loader | ≤ 1.4 | Yes |