CyberSec.Space Logo
Back to CVE Browser

CVE-2019-1003030

Known Exploited (CISA KEV)CRITICAL
9.9
CVSS Severity Score
EPSS Score27.9370%
EPSS Percentile94.86th
PublishedMar 8, 2019
Last ModifiedOct 24, 2025

Vulnerability Description

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Affected Platforms (CPE)

πŸ“¦
Jenkins

Pipeline\

<= 2.63
πŸ“¦
Redhat

Openshift Container Platform

= 3.11

References & Advisories

Related Vulnerabilities