CVE-2019-1003031
published 2019-03-08CVE-2019-1003031: A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows…
PriorityP356critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
3.39%
87.5th percentile
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | appdynamics_dashboard_plugin | — | — |
| jenkins | azure_vm_agents_plugin | — | — |
| jenkins | azure_vm_in_azure_vm_agents_plugin | — | — |
| jenkins | bitbar_run-in-cloud_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | deploy_plugin | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | ids_in_azure_vm_agents_plugin | — | — |
| jenkins | ids_to_allow_administrators_configuring_the_plugin | — | — |
| jenkins | job_dsl_plugin | — | — |
| jenkins | matrix_project | <= 1.13 | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins | rabbit-mq_publisher_plugin | — | — |
| jenkins | rabbitmq_in_rabbit-mq_publisher_plugin | — | — |
| jenkins | repository_connector_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | this_allowed_users_able_to_control_the_plugin | — | — |
| jenkins_project | jenkins_matrix_project_plugin | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
vendor_redhat·2019-03-06·CVSS 9.9
CVE-2019-1003031 [CRITICAL] CWE-96 jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
A flaw was found in the Jenkins Matrix Project plugin version 1.13. An attacker with Job/Configure permission can bypass the sandbox and can execute arbitrary code on the Jenkins master JVM. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.10) - Will not fix
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.6) - Will not
Jenkins
Jenkins Security Advisory 2019-03-06
vendor_jenkins·2019-03-06·CVSS 9.9
CVE-2019-1003029 [CRITICAL] Jenkins Security Advisory 2019-03-06
Title: Jenkins Security Advisory 2019-03-06
Jenkins Security Advisory 2019-03-06
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
AppDynamics Dashboard
Plugin
Azure VM Agents
Plugin
Bitbar Run-in-Cloud
Plugin
Email Extension
Plugin
Groovy
Plugin
Job DSL
Plugin
Matrix Project
Plugin
OSF Bui
OSV
Script security sandbox bypass in Matrix Project Plugin
osv·2022-05-13
CVE-2019-1003031 [CRITICAL] Script security sandbox bypass in Matrix Project Plugin
Script security sandbox bypass in Matrix Project Plugin
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
GHSA
Script security sandbox bypass in Matrix Project Plugin
ghsa·2022-05-13
CVE-2019-1003031 [CRITICAL] CWE-693 Script security sandbox bypass in Matrix Project Plugin
Script security sandbox bypass in Matrix Project Plugin
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
No detection rules found.
No public exploits indexed.
arXiv
eyeballvul: a future-proof benchmark for vulnerability detection in the wild
arxiv_fulltext·2024-07-13
eyeballvul: a future-proof benchmark for vulnerability detection in the wild
*-0.5cm
center
[email protected]
center
## Abstract
Long contexts of recent LLMs have enabled a new use case: asking models to find security vulnerabilities in entire codebases. To evaluate model performance on this task, we introduce eyeballvul: a benchmark designed to test the vulnerability detection capabilities of language models at scale, that is sourced and updated weekly from the stream of published vulnerabilities in open-source repositories. The benchmark consists of a list of revisions in different repositories, each associated with the list of known vulnerabilities present at that revision. An LLM-based scorer is used to compare the list of possible vulnerabilities returned by a model to the list of known vulnerabilities for each revision. As of July 2024, eyeballvu
Bugzilla
CVE-2019-1003031 jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
bugzilla·2019-03-18·CVSS 9.9
CVE-2019-1003031 [CRITICAL] CVE-2019-1003031 jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
CVE-2019-1003031 jenkins-matrix-project-plugin: sandbox bypass in matrix project plugin
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
Reference:
https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1339
Discussion:
External References:
https://jenkins.io/security/advisory/2019-03-06/#SECURITY-1339
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.11
Via RHSA-2019:0739 https://access.redhat.com/errata/RHSA-2019:0739
2019-03-08
Published