CyberSec.Space Logo
Back to CVE Browser

CVE-2019-1003029

Known Exploited (CISA KEV)CRITICAL
9.9
CVSS Severity Score
EPSS Score58.8920%
EPSS Percentile96.24th
PublishedMar 8, 2019
Last ModifiedOct 24, 2025

Vulnerability Description

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Affected Platforms (CPE)

πŸ“¦
Jenkins

Script Security

<= 1.53
πŸ“¦
Redhat

Openshift Container Platform

= 3.11

References & Advisories

Related Vulnerabilities