{
  "threat_severity" : "Important",
  "public_date" : "2019-08-01T00:00:00Z",
  "bugzilla" : {
    "description" : "jenkins-plugin-script-security: Sandbox bypass through type casts in Script Security Plugin",
    "id" : "1735515",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1735515"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-704",
  "details" : [ "A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.", "A flaw was found in Jenkins Script Security plugin. Sandbox protection could be circumvented by casting crafted objects to other types allowing an attacker to specify sandboxed scripts to invoke constructors that weren't previously whitelisted. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability." ],
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "release_date" : "2019-09-04T00:00:00Z",
    "advisory" : "RHSA-2019:2651",
    "cpe" : "cpe:/a:redhat:openshift:3.11::el7",
    "package" : "jenkins-2-plugins-0:3.11.1566492396-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.1",
    "release_date" : "2019-09-11T00:00:00Z",
    "advisory" : "RHSA-2019:2662",
    "cpe" : "cpe:/a:redhat:openshift:4.1::el7",
    "package" : "jenkins-2-plugins-0:4.1.1567707934-1.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 3.10",
    "fix_state" : "Will not fix",
    "package_name" : "jenkins-script-security-plugin",
    "cpe" : "cpe:/a:redhat:openshift:3.10"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.9",
    "fix_state" : "Will not fix",
    "package_name" : "jenkins-script-security-plugin",
    "cpe" : "cpe:/a:redhat:openshift:3.9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-10355\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-10355\nhttps://jenkins.io/security/advisory/2019-07-31/#SECURITY-1465%20(1)" ],
  "name" : "CVE-2019-10355",
  "csaw" : false
}