SB2019080738 - Remote code execution in Simple Travis Pipeline Runner plugin for Jenkins
Published: August 7, 2019 Updated: October 4, 2019
Security Bulletin ID
SB2019080738
Severity
High
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security Features (CVE-ID: CVE-2019-10380)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software specifies unsafe values in its custom Script Security whitelist. This custom whitelist allows the use of methods that can be used to bypass Script Security sandbox protection. A remote authenticated attacker can execute arbitrary code on any Jenkins instance with this plugin installed.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.