Jenkins Job DSL 1.62 for Jenkins

CPE Details

Jenkins Job DSL 1.62 for Jenkins
1.62
2019-03-12
15h55 +00:00
2019-03-12
15h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:job_dsl:1.62:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

job_dsl

Version

1.62

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-1003034 2019-03-08 20h00 +00:00 A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScriptLoader.groovy, job-dsl-plugin/build.gradle, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/JobDslWhitelist.groovy, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/SandboxDslScriptLoader.groovy that allows attackers with control over Job DSL definitions to execute arbitrary code on the Jenkins master JVM.
9.9
Critical