Critical severity9.9CISA KEVNVD Advisory· Published Mar 8, 2019· Updated Jun 17, 2026
CVE-2019-1003030
CVE-2019-1003030
Description
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-cpsMaven | < 2.64 | 2.64 |
Affected products
4- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- Range: 2.63 and earlier
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/159603/Jenkins-2.63-Sandbox-Bypass.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/bid/107476nvdBroken LinkThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:0739nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-r6mc-mrvr-23crghsaADVISORY
- jenkins.io/security/advisory/2019-03-06/nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2019-1003030ghsaADVISORY
- jenkins.io/security/advisory/2019-03-06/ghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
0No linked articles in our index yet.