Skip to content
COOEY

EXPOSURES › CVE-2019-1003030

CVE-2019-1003030

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1003030 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

The Jenkins Matrix Project Plugin contained an unpatched remote code execution vulnerability that allowed sandbox escape and arbitrary code execution.

The Jenkins Matrix Project Plugin suffered from an unpatched remote code execution vulnerability that allowed attackers to escape the sandbox and execute arbitrary code on the server. This failure is critical for DIB organizations because it directly enables remote code execution, violates CMMC/NIST 800-171 requirements for patch management, and exposes CI/CD pipelines to compromise. Organizations must ensure all Jenkins plugins are patched and monitored for KEV-listed vulnerabilities.

Shame score — The vulnerability was actively exploited in the wild (KEV-listed) and allowed remote code execution, representing a negligent failure to patch a known, high-severity vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.