CVE-2019-1003040: Critical severity jenkins script security vulnerability
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
Other sources
Sandbox projection in the Jenkins Script Security and Pipeline: Groovy Plugins could be circumvented through methods supporting type casts and type coercion. This allowed attackers to invoke constructors for arbitrary types.
External Reference:
https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1353
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003040?
CVE-2019-1003040 is classified as a high severity vulnerability due to its ability to allow attackers to execute arbitrary code.
How do I fix CVE-2019-1003040?
To fix CVE-2019-1003040, you should upgrade to Jenkins Script Security Plugin version 1.56 or later.
What affects CVE-2019-1003040?
CVE-2019-1003040 affects Jenkins Script Security Plugin versions 1.55 and earlier.
Can CVE-2019-1003040 be exploited?
Yes, CVE-2019-1003040 can be exploited to invoke arbitrary constructors in sandboxed scripts, leading to serious security risks.
What is the impact of CVE-2019-1003040?
The impact of CVE-2019-1003040 includes the potential for unauthorized execution of arbitrary code in a Jenkins environment.