Junglewise Threat Intelligence

CVE-2019-1003030: Sandbox bypass in Jenkins Pipeline: Groovy Plugin

CVE-2019-1003030 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Vendors: Jenkins, Maven.

Executive brief

A sandbox bypass vulnerability in the Jenkins Pipeline: Groovy Plugin allows attackers who can control pipeline scripts to execute arbitrary code on the Jenkins master JVM. This occurs due to improper sandbox restrictions in CpsGroovyShell.java, leading to remote code execution.

Affected products

  • Jenkins Pipeline: Groovy Plugin 2.63 and earlier
  • Jenkins Matrix Project Plugin (none specified)

Timeline

  • 2019-03-06: advisory: Vendor security advisory published by Jenkins.
  • 2019-03-12: disclosed: Initial NVD analysis.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats