Jenkins Pipeline是一套插件,支持将持续交付管道实施和集成到 Jenkins 中。 CloudBees Pipeline: Declarative Plugin 1.3.3及之前版本中的pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy文件存在安全漏洞。该漏洞允许具有Overall/Read权限的攻击者向HTTP端点提供
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Jenkins project | Pipeline: Declarative Plugin | 1.3.3 and earlier | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-1003000 | Jenkins Script Security Plugin 安全漏洞 | |
| CVE-2019-1003001 | CloudBees Jenkins Pipeline: Groovy Plugin 安全特征问题漏洞 | |
| CVE-2019-1003003 | CloudBees Jenkins 代码问题漏洞 | |
| CVE-2019-1003004 | CloudBees Jenkins 代码问题漏洞 |
No comments yet