#VU21380 Permissions, Privileges, and Access Controls in Kubernetes Pipeline - Kubernetes Steps - CVE-2019-10417
Published: September 27, 2019
Kubernetes Pipeline - Kubernetes Steps
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected software defines a custom whitelist for all scripts protected by the Script Security sandbox. This custom whitelist allows the use of methods that can be used to bypass Script Security sandbox protection. A remote authenticated attacker can execute arbitrary code on any Jenkins instance with this plugin installed.