Skip to content
COOEY

EXPOSURES › CVE-2019-1003029

CVE-2019-1003029

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1003029 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

An attacker bypassed the Jenkins Script Security Plugin sandbox, enabling arbitrary code execution in Jenkins pipelines.

The Jenkins Script Security Plugin failed to properly enforce its sandbox, allowing attackers to bypass protections and execute arbitrary code within Jenkins pipelines. This failure impacts DIB organizations relying on Jenkins for CI/CD, as it enables pipeline compromise, credential theft, and lateral movement. Organizations must upgrade the plugin and audit pipeline configurations for sandbox bypass indicators.

Shame score — A known sandbox bypass vulnerability in a widely used CI/CD plugin was actively exploited in the wild, demonstrating negligent security practices and avoidable exposure for Jenkins users.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.