CVE-2019-1003029 is a critical sandbox bypass vulnerability affecting Jenkins Script Security Plugin versions 1.53 and earlier, as well as Red Hat OpenShift Container Platform. This flaw allows authenticated attackers with read permissions to execute arbitrary code on the Jenkins master JVM. With a CVSS score of 9.9 (Critical) and an EPSS score of 0.9219, it poses a severe risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited, listed in CISA's KEV catalog, and has a public Metasploit module available, indicating widespread exploitability and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.53CPE matchmatch criteria | cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.