CVE-2019-1003030
KEV PoC largeSandbox Bypass Enables RCE in Jenkins Pipeline: Groovy Plugin
CISA: Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier, in the CpsGroovyShell.java component, allowing Groovy scripts to escape the plugin's intended script sandbox. It is triggered when a Jenkins controller executes a pipeline script that an attacker can control — for example, a low-privileged authenticated user with permission to define or edit a job's pipeline definition. Successful exploitation yields arbitrary code execution in the Jenkins master JVM, giving the attacker full control of the controller and, per the CVSS scope change, impact that extends to the wider Jenkins environment including connected build agents. Affected deployments include Jenkins controllers running the vulnerable plugin — CISA's KEV entry names the Matrix Project Plugin — as well as Jenkins distributed through Red Hat OpenShift Container Platform. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), confirming in-the-wild exploitation, and EPSS of ~96.9% (100th percentile) indicates an extremely high probability of near-term exploitation.
What to do: Apply updates per vendor instructions (the CISA KEV required action), upgrading the Pipeline: Groovy Plugin to a version later than 2.63 and deploying updated Jenkins images where applicable (including Red Hat OpenShift Container Platform). Restrict which users can create or edit pipeline scripts, and audit job configurations for attacker-controlled or recently modified pipeline definitions. Because the flaw is KEV-listed and actively exploited, check controllers for signs of compromise, such as unexpected processes or build activity in the master JVM.
| Jenkins (jenkinsci) Pipeline: Groovy Plugin | 2.63 and earlier (per CVE description; CISA KEV entry names the Matrix Project Plugin) |
| Jenkins (jenkinsci) Matrix Project Plugin (as named in CISA's affected-product listing) | — |
| Red Hat OpenShift Container Platform (ships affected Jenkins plugin components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
- Affected
- Jenkins Matrix Project Plugin
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown