CVE-2019-1003029: Jenkins Script Security Plugin Sandbox Bypass Vulnerability
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
Other sources
Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkins-script-security-pluginto a version that resolves this vulnerability.Fixed in 1.54 - Upgrade
Upgrade
maven/org.jenkins-ci.plugins:script-securityto a version that resolves this vulnerability.Fixed in 1.54
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003029?
CVE-2019-1003029 is classified as a medium severity vulnerability.
How do I fix CVE-2019-1003029?
To fix CVE-2019-1003029, upgrade the Jenkins Script Security Plugin to version 1.54 or later.
What products are affected by CVE-2019-1003029?
CVE-2019-1003029 affects Jenkins Script Security Plugin versions 1.53 and earlier.
Is CVE-2019-1003029 a sandbox bypass vulnerability?
Yes, CVE-2019-1003029 allows attackers to bypass the sandbox protections of the Jenkins Script Security Plugin.
What versions of Jenkins are impacted by CVE-2019-1003029?
Jenkins versions with the Script Security Plugin 1.53 and earlier are impacted by CVE-2019-1003029.