ZeroHour

CVE-2019-10306

CVSS 3.1
9.9 critical
EPSS
2%p83
Published
()
Modified
Description

A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.

Vendors
jenkins
Products
ontrack
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.