CVE-2019-1003000
PoC ×3—CVSS 3.1
8.8 high
EPSS
98%p100
Published
()
Modified
Description
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
In the news0 stories
No ingested article mentions this CVE yet.