← back
CVE-2019-1003002

CVE-2019-1003002

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 81%
from disclosure to weapon28 days
Published on NVDJan 22
1st PoC+28d
metasploitJan 8
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
5 products (9 components)
Red Hat OpenShift Container Platform 3.10 · Red Hat OpenShift Container Platform 3.6 · Red Hat OpenShift Container Platform 3.7 · Red Hat OpenShift Container Platform 3.9 · Red Hat OpenShift Container Platform 3.5
none_available: Affected
Fixed
1 product (83 components)
Red Hat OpenShift Container Platform 3.11
Not affected
4 products (5 components)because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4 · Red Hat OpenShift Container Platform 3.2 · Red Hat OpenShift Container Platform 3.3 · Red Hat OpenShift Container Platform 3.4
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.