CVE-2019-1003029
CVE Published | 2019-03-08 |
---|---|
Related Vendor(s) | jenkins, redhat |
Related Product(s) | openshift_container_platform, script_security |
Exploitation Reported (CISA KEV) | 2022-04-25 |
CVSS 3 Base Score | 9.9 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph