Permissions, Privileges, and Access Controls in Script Security - CVE-2019-10431

 

Permissions, Privileges, and Access Controls in Script Security - CVE-2019-10431

Published: October 3, 2019


Vulnerability identifier: #VU21522
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10431
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the sandbox protection in the affected plugin can be circumvented through default parameter expressions in constructors. A remote authenticated attacker can specify and run sandboxed scripts to execute arbitrary code in the context of the Jenkins master JVM.


Affected software

Script Security
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-10431

Install updates from vendor's website.

Script Security - update to 1.65
Red Hat OpenShift Container Platform - addressed in versions 4.1.27, 4.2.10

External References

Related Security Bulletins