Back to overview

CVE-2019-1003030

CRITICAL KEV CISA Exploitation: ACTIVE
9.9
CVSS 3.1
Description
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Metadata

CVE ID
CVE-2019-1003030
State
PUBLISHED
Assigner
jenkins
Reserved
2019-03-08 00:00 UTC
Published
2019-03-08 21:00 UTC
Last updated
2025-10-21 23:45 UTC
Primary CWE
CWE-693
CWE-693 Protection Mechanism Failure
Vendor / Product
Jenkins project / Jenkins Pipeline: Groovy Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
Vendor
Jenkins
Product
Matrix Project Plugin
Added to KEV
2022-03-25
Due date
2022-04-15
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
Affected products (1)
VendorProductPlatformVersions
Jenkins project Jenkins Pipeline: Groovy Plugin 2.63 and earlier
Weakness (CWE)
CWESourceDescription
CWE-693 adp CWE-693 Protection Mechanism Failure
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview