← back
CVE-2019-1003002

CVE-2019-1003002

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 82%
from disclosure to weapon28 days
Published on NVDJan 22
1st PoC+28d
metasploitJan 8
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.