VYPR
High severityNVD Advisory· Published Feb 6, 2019· Updated Sep 17, 2024

CVE-2019-1003007

CVE-2019-1003007

Description

Cross-site request forgery in Jenkins Warnings Plugin 5.0.0 and earlier allows attackers to execute arbitrary code via a form validation endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site request forgery in Jenkins Warnings Plugin 5.0.0 and earlier allows attackers to execute arbitrary code via a form validation endpoint.

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Warnings Plugin versions 5.0.0 and earlier, specifically in the form validation HTTP endpoint defined in src/main/java/hudson/plugins/warnings/GroovyParser.java. The endpoint does not require a CSRF token, allowing an attacker to trigger arbitrary Groovy script compilation on the Jenkins controller without appropriate sandbox protection [1][3].

Exploitation

An attacker with Overall/Read access to Jenkins can craft a malicious link or form and trick an authenticated Jenkins user with sufficient permissions to submit a request to the vulnerable form validation endpoint. The request includes a Groovy script with AST-transforming annotations such as @Grab, which bypass the sandbox and allow execution of arbitrary code on the Jenkins controller [1].

Impact

Successful exploitation enables an attacker to execute arbitrary code on the Jenkins controller, potentially leading to full system compromise. The attacker can perform any action that the Jenkins controller process can, including reading credentials, installing malware, or pivoting to other systems [1][3].

Mitigation

Jenkins released a fix in a subsequent version of the Warnings Plugin that applies a safe Groovy compiler configuration, preventing the use of unsafe AST-transforming annotations. Users should upgrade to the latest version of the Warnings Plugin as recommended in the Jenkins security advisory [1]. No workaround is available; patching is the only mitigation [3].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jvnet.hudson.plugins:warningsMaven
< 5.0.15.0.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.