SB2019080738 - Remote code execution in Simple Travis Pipeline Runner plugin for Jenkins



SB2019080738 - Remote code execution in Simple Travis Pipeline Runner plugin for Jenkins

Published: August 7, 2019 Updated: October 4, 2019

Security Bulletin ID SB2019080738
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security Features (CVE-ID: CVE-2019-10380)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the affected software specifies unsafe values in its custom Script Security whitelist. This custom whitelist allows the use of methods that can be used to bypass Script Security sandbox protection. A remote authenticated attacker can execute arbitrary code on any Jenkins instance with this plugin installed.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.