Back
CVE-2019-10431
CRITICAL
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
Published: Oct 1, 2019
Modified: Jun 17, 2026
CWE-94
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| jenkins | script_security | * |
GitHub Security Advisory GHSA-72gx-qq2m-6xr2
Improper Control of Generation of Code in Jenkins Script Security Plugin
maven
org.jenkins-ci.plugins:script-security
<= 1.64
Fixed: 1.65
References (10)
- http://www.openwall.com/lists/oss-security/2019/10/01/2 Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4055
- https://access.redhat.com/errata/RHSA-2019:4089
- https://access.redhat.com/errata/RHSA-2019:4097
- https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/10/01/2 Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4055
- https://access.redhat.com/errata/RHSA-2019:4089
- https://access.redhat.com/errata/RHSA-2019:4097
- https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1579 Vendor Advisory
Risk Scores
CVSS Score
9.9 / 10
EPSS Score
2.70%
Top 15% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub