GHSA-mj9c-vjp9-pggh
CRITICALCVE-2019-10458Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
- Affected
- <= 1.3.1
- Fixed in
- not stated
- Published
- 2022-05-24
- Source
- github