← back
CVE-2019-1003001observed exploitation

CVE-2019-1003001

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 86%
from disclosure to weapon28 days
Published on NVDJan 22
1st PoC+28d
metasploitJan 8
VulnCheck+1910d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.