ZeroHour

CVE-2019-10458

CVSS 3.1
9.9 critical
EPSS
2%p79
Published
()
Modified
Description

Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.

Vendors
jenkins
Products
puppet enterprise pipeline
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.