Permissions, Privileges, and Access Controls in Script Security - CVE-2019-10431
Published: October 3, 2019
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the sandbox protection in the affected plugin can be circumvented through default parameter expressions in constructors. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.
Affected software
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-10431
Red Hat OpenShift Container Platform - addressed in versions 4.1.27, 4.2.10