CVE-2019-10390

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/08/2019
Last modified:
25/10/2023

Description

A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:splunk:*:*:*:*:*:jenkins:*:* 1.7.4 (including)