CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in...
- Published
- Jan 22, 2019
- Updated
- Aug 5, 2024
- Assigning CNA
- jenkins
- Evidence observed
- Feb 19, 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in...
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
PoC exploit for Jenkins Script Security Pipeline plugin remote code execution vulnerability (CVE-2019-1003000), implemented in Python for penetration testing and vulnerability verification.
Notes about attacking Jenkins servers
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
orange · java · Feb 19, 2019
wetw0rk · java · Feb 25, 2019
Metasploit · java · Mar 19, 2019
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.