CVE-2019-1003030
Description
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
In plain language
AI Act nowCVE-2019-1003030 is a Jenkins Pipeline Groovy Plugin security bug where someone who can change a pipeline script can break out of the sandbox and run commands on your Jenkins server—this is serious and should be fixed immediately if you use this Jenkins plugin in production.
CVE-2019-1003030 is a sandbox bypass in Jenkins Pipeline: Groovy Plugin (workflow-cps) (Groovy Plugin 2.63 and earlier) that allows attackers who can control Jenkins Pipeline Groovy scripts to execute arbitrary code on the Jenkins master/JVM over the network.
What to do now
- Check your Jenkins Pipeline: Groovy Plugin (workflow-cps) version; if it is 2.63 or earlier, treat your Jenkins as affected.
- Upgrade the Jenkins Pipeline: Groovy Plugin (workflow-cps) to 2.64 or later.
- If you cannot upgrade right away, immediately stop/limit who can modify pipeline scripts and remove untrusted pipeline script sources until the upgrade is complete.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-1003030 and every CVE in our database. Create a free account — no credit card required.
Create Free Account