Jenkins Pipeline: Declarative 1.1.7 for Jenkins

CPE Details

Jenkins Pipeline: Declarative 1.1.7 for Jenkins
1.1.7
2019-04-16
10h46 +00:00
2019-04-16
10h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:pipeline\:_declarative:1.1.7:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

pipeline:_declarative

Version

1.1.7

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-1003002 2019-01-22 13h00 +00:00 A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
8.8
High