CVE-2019-10400

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.2medium3.x
0246810

CVSS Score: 4.2/10

All CVSS Scores

CVSS 3.x
4.2

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS 2.0
4.9

Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Description

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

Vulnerable Software (1)

Type: Configuration

Vendor: jenkins

Product: script_security

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*",      "versionEndIncluding": "1.62",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd