Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-1003001Static Code Injection in Jenkins Pipeline

CWE-96Static Code Injection14 documents12 sources
Severity
8.8HIGHNVD
EPSS
93.9%
top 0.12%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 22
Latest updateMay 13

Description

A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5jenkins_project/pipeline_groovy_plugin2.61 and earlier

Also affects: Openshift Container Platform 3.11

🔴Vulnerability Details

4
GHSA
Jenkins Groovy Plugin sandbox bypass vulnerability2022-05-13
OSV
Jenkins Groovy Plugin sandbox bypass vulnerability2022-05-13
CVEList
CVE-2019-1003001: A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 22019-01-22
VulnCheck
Pipeline: Groovy Plugin 2.61 and earlier Sandbox Bypass2019

💥Exploits & PoCs

3
Exploit-DB
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)2019-03-19
Exploit-DB
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)2019-02-19
Metasploit
Jenkins ACL Bypass and Metaprogramming RCE

🔍Detection Rules

1
Suricata
ET EXPLOIT Jenkins Plugin Script RCE Exploit Attempt (CVE-2019-1003001)2021-07-28

📋Vendor Advisories

2
Red Hat
jenkins-plugin-workflow-cps: Sandbox Bypass in Pipeline: Groovy Plugin2019-01-08
Jenkins
Jenkins Security Advisory 2019-01-082019-01-08

🕵️Threat Intelligence

2
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability2019-05-07
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability2019-05-07

💬Community

1
Bugzilla
CVE-2019-1003001 jenkins-plugin-workflow-cps: Sandbox Bypass in Pipeline: Groovy Plugin2019-01-25
CVE-2019-1003001 — Static Code Injection in Jenkins | cvebase