CVE-2019-1003030 is a critical sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin versions 2.63 and earlier, affecting Jenkins and Red Hat OpenShift Container Platform. It allows attackers with control over pipeline scripts to execute arbitrary code on the Jenkins master JVM. With a CVSS score of 9.9, this vulnerability is easily exploitable over the network with low privileges, leading to complete compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, has publicly available exploit code (EDB-48904), and has garnered significant community discussion, indicating its high risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.63CPE matchmatch criteria | cpe:2.3:a:jenkins:pipeline\:_groovy:*:*:*:*:*:jenkins:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.