VYPR
Critical severityCISA KEVNVD Advisory· Published Mar 8, 2019· Updated Oct 21, 2025

CVE-2019-1003030

CVE-2019-1003030

Description

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins.workflow:workflow-cpsMaven
< 2.642.64

Affected products

1
  • Jenkins project/Jenkins Pipeline: Groovy Pluginv5
    Range: 2.63 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.