Описание
Incorrect Authorization in Puppet Enterprise Pipeline Jenkins Plugin
Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
Пакеты
Наименование
org.jenkins-ci.plugins.workflow:puppet-enterprise-pipeline
maven
Затронутые версииВерсия исправления
<= 1.3.1
Отсутствует
Связанные уязвимости
CVSS3: 9.9
nvd
больше 6 лет назад
Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.