Critical severity9.9CISA KEVNVD Advisory· Published Mar 8, 2019· Updated Jun 17, 2026
CVE-2019-1003029
CVE-2019-1003029
Description
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:script-securityMaven | < 1.54 | 1.54 |
Affected products
4cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:script_security:*:*:*:*:*:jenkins:*:*range: <=1.53
- (no CPE)range: 1.53 and earlier
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/bid/107476nvdBroken LinkThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:0739nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-xvxq-hq48-xphmghsaADVISORY
- jenkins.io/security/advisory/2019-03-06/nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-1003029ghsaADVISORY
- jenkins.io/security/advisory/2019-03-06/ghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
0No linked articles in our index yet.