CVE Vulnerabilities

CVE-2019-1003030

Published: Mar 08, 2019 | Modified: Oct 25, 2023
CVSS 3.x
9.9
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Affected Software

Name Vendor Start Version End Version
Pipeline:_groovy Jenkins * 2.63 (including)
Red Hat OpenShift Container Platform 3.11 RedHat jenkins-2-plugins-0:3.11.1552336312-1.el7 *

References