High severityNVD Advisory· Published Jan 22, 2019· Updated Aug 5, 2024
CVE-2019-1003002
CVE-2019-1003002
Description
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkinsci.plugins:pipeline-model-definitionMaven | < 1.3.4.1 | 1.3.4.1 |
Affected products
2- Range: 1.3.3 and earlier
Patches
Vulnerability mechanics
References
10- www.exploit-db.com/exploits/46572/mitreexploitx_refsource_EXPLOIT-DB
- access.redhat.com/errata/RHBA-2019:0326ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHBA-2019:0327ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-x6jx-cxg3-mgghghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-1003002ghsaADVISORY
- packetstormsecurity.com/files/152132/Jenkins-ACL-Bypass-Metaprogramming-Remote-Code-Execution.htmlghsax_refsource_MISCWEB
- www.rapid7.com/db/modules/exploit/multi/http/jenkins_metaprogrammingghsax_refsource_MISCWEB
- github.com/jenkinsci/pipeline-model-definition-plugin/commit/083abd96e68fd89f556a0cd53db5f878dbf09b92ghsaWEB
- jenkins.io/security/advisory/2019-01-08/ghsax_refsource_CONFIRMWEB
- www.exploit-db.com/exploits/46572ghsaWEB
News mentions
0No linked articles in our index yet.