CVE-2019-10306

Description

A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.

Risk Information

Base Score
9.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.28

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10306 are fixed in Jenkins - ontrack 3.4.1Windows
Vulnerabilities CVE-2019-10306 are fixed in Jenkins - ontrack for Linux 3.4.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234