CVE-2019-10306: Jenkins Ontrack

Critical severity, CVSS 9.9. EPSS: 2.3% chance of exploitation in the next 30 days.

A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.

Affected products

  • Jenkins Ontrack: up to and including 3.4

Published 2019-04-18. Last modified 2026-06-17.