EXPOSURES › CVE-2019-1003029
CVE-2019-1003029
HIGH ⌖ ON CISA KEV · EXPLOITEDAn attacker bypassed the Jenkins Script Security Plugin sandbox, enabling arbitrary code execution in Jenkins pipelines.
The Jenkins Script Security Plugin failed to properly enforce its sandbox, allowing attackers to bypass protections and execute arbitrary code within Jenkins pipelines. This failure impacts DIB organizations relying on Jenkins for CI/CD, as it enables pipeline compromise, credential theft, and lateral movement. Organizations must upgrade the plugin and audit pipeline configurations for sandbox bypass indicators.
Shame score — A known sandbox bypass vulnerability in a widely used CI/CD plugin was actively exploited in the wild, demonstrating negligent security practices and avoidable exposure for Jenkins users.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.