CVE-2019-10306: Jenkins Ontrack
Critical severity, CVSS 9.9. EPSS: 2.3% chance of exploitation in the next 30 days.
A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.
Affected products
- Jenkins Ontrack: up to and including 3.4
Published 2019-04-18. Last modified 2026-06-17.