CVE-2019-1003029
Jenkins Script Security Plugin Sandbox Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
- CVSS 3.1
- 9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 73.85% probability · 99th percentile
- CISA KEV
- Listed 25 April 2022 · due 16 May 2022
- Affected
- jenkins/script security · redhat/openshift container platform
- Source
- jenkinsci-cert@googlegroups.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-1003029
References
- http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107476Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0739Third Party Advisory
- https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1336%20%281%29Third Party Advisory
- http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107476Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0739Third Party Advisory
- https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1336%20%281%29Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1003029US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.