Cyber Resilience

CVE-2019-1003029

Jenkins Script Security ≤ 1.53

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
08 March 2019
Modified
24 October 2025
KEV Added
25 April 2022
CVSS Score v3.1 9.9
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.74 99.4th percentile
Risk Priority 94 floored blend · peak EPSS

Summary

CVE-2019-1003029 is a critical-severity an unspecified weakness vulnerability in Jenkins Script Security. Its CVSS base score is 9.9 (Critical).

Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability CVE-2019-1003029 is a sandbox bypass affecting the Jenkins Script Security Plugin in versions 1.53 and earlier. It resides in the GroovySandbox.java and SecureGroovyScript.java components and permits execution of code outside the intended Groovy sandbox on the Jenkins master JVM.

Attackers holding the Overall/Read permission can exploit the flaw over the network to run arbitrary code on the master with full impact to confidentiality, integrity, and availability. The vulnerability is rated 9.9 under CVSS 3.1 with an attack vector of network, low complexity, and no user interaction required.

Public references include the Jenkins security advisory for SECURITY-1336, Red Hat errata RHSA-2019:0739, and multiple exploit disclosures on Packet Storm and SecurityFocus that point to available updates for the plugin.

EU & UK References

Vulnerability Data

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

CWE(s)
KEV Date Added
25 April 2022

Related Threats

CVEs Like This One

CVE-2019-1003000Same product: Jenkins Script Security
CVE-2018-1000861Same product: Redhat Openshift Container Platformboth on KEV
CVE-2019-1003030Same product: Redhat Openshift Container Platformboth on KEV
CVE-2015-5317Same vendor: Jenkinsboth on KEV
CVE-2019-1003001Same product: Redhat Openshift Container Platform
CVE-2015-8103Same product: Redhat Openshift Container Platform
CVE-2019-7609Same product: Redhat Openshift Container Platformboth on KEV
CVE-2019-1003002Same product: Redhat Openshift Container Platform
CVE-2026-10533Same product: Redhat Openshift Container Platform
CVE-2024-23897Same vendor: Jenkinsboth on KEV

Affected Assets

jenkins
script security
≤ 1.53
redhat
openshift container platform
3.11

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References