CVE-2019-1003029

CVE Published 2019-03-08
Related Vendor(s) jenkins, redhat
Related Product(s) openshift_container_platform, script_security
Exploitation Reported (CISA KEV) 2022-04-25
CVSS 3 Base Score 9.9 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References