#VU22160 Permissions, Privileges, and Access Controls in Puppet Enterprise Pipeline - CVE-2019-10458
Published: October 22, 2019
Puppet Enterprise Pipeline
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected plugin specifies unsafe values in its custom Script Security whitelist. A remote authenticated attacker can bypass Script Security sandbox protection and execute arbitrary code on any Jenkins instance with this plugin installed.