ZeroHour

CVE-2019-10380

CVSS 3.1
8.8 high
EPSS
2%p77
Published
()
Modified
Description

Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.

Vendors
jenkins
Products
simple travis pipeline runner
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.