CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-1003030

Known Exploited (CISA KEV)CRITICAL
9.9
CVSS Severity Score
EPSS Score27.9370%
EPSS Percentile94.86th
Published2019年3月8日
Last Modified2025年10月24日

Vulnerability Description

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Affected Platforms (CPE)

📦
Jenkins

Pipeline\

<= 2.63
📦
Redhat

Openshift Container Platform

= 3.11

References & Advisories

相关漏洞威胁