Junglewise Threat Intelligence

CVE-2019-1003029: Sandbox bypass in Script Security Plugin

CVE-2019-1003029 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Technologies: Jenkins Script Security Plugin. Vendors: Jenkins Project, Maven, Jenkins.

Executive brief

A sandbox bypass vulnerability in the Jenkins Script Security Plugin allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. The flaw exists in the GroovySandbox.java and SecureGroovyScript.java components due to a protection mechanism failure.

Affected products

  • Jenkins Project Script Security Plugin 1.53 and earlier

Timeline

  • 2019-03-06: disclosed: Vendor advisory SECURITY-1336 published.
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-04-25: advisory: NVD publication date.

Related threats