← back
CVE-2019-1003001observed exploitation

CVE-2019-1003001

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 86%
from disclosure to weapon28 days
Published on NVDJan 22
1st PoC+28d
metasploitJan 8
VulnCheck+1910d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
8 products (12 components)
Red Hat OpenShift Container Platform 3.10 · Red Hat OpenShift Container Platform 3.6 · Red Hat OpenShift Container Platform 3.7 · Red Hat OpenShift Container Platform 3.9 · Red Hat OpenShift Container Platform 3.2 · and others 3
none_available: Affected
Fixed
1 product (83 components)
Red Hat OpenShift Container Platform 3.11
Not affected
1 product (2 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.