CVE-2019-1003029
Jenkins Script Security ≤ 1.53
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSummary
CVE-2019-1003029 is a critical-severity an unspecified weakness vulnerability in Jenkins Script Security. Its CVSS base score is 9.9 (Critical).
Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability CVE-2019-1003029 is a sandbox bypass affecting the Jenkins Script Security Plugin in versions 1.53 and earlier. It resides in the GroovySandbox.java and SecureGroovyScript.java components and permits execution of code outside the intended Groovy sandbox on the Jenkins master JVM.
Attackers holding the Overall/Read permission can exploit the flaw over the network to run arbitrary code on the master with full impact to confidentiality, integrity, and availability. The vulnerability is rated 9.9 under CVSS 3.1 with an attack vector of network, low complexity, and no user interaction required.
Public references include the Jenkins security advisory for SECURITY-1336, Red Hat errata RHSA-2019:0739, and multiple exploit disclosures on Packet Storm and SecurityFocus that point to available updates for the plugin.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-5866
Vulnerability Data
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
- CWE(s)
- KEV Date Added
- 25 April 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.