EXPOSURES › CVE-2019-1003030
CVE-2019-1003030
HIGH ⌖ ON CISA KEV · EXPLOITEDThe Jenkins Matrix Project Plugin contained an unpatched remote code execution vulnerability that allowed sandbox escape and arbitrary code execution.
The Jenkins Matrix Project Plugin suffered from an unpatched remote code execution vulnerability that allowed attackers to escape the sandbox and execute arbitrary code on the server. This failure is critical for DIB organizations because it directly enables remote code execution, violates CMMC/NIST 800-171 requirements for patch management, and exposes CI/CD pipelines to compromise. Organizations must ensure all Jenkins plugins are patched and monitored for KEV-listed vulnerabilities.
Shame score — The vulnerability was actively exploited in the wild (KEV-listed) and allowed remote code execution, representing a negligent failure to patch a known, high-severity vulnerability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.