CVE-2019-1003041: Critical severity jenkins pipeline vulnerability
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
Other sources
Sandbox projection in the Jenkins Script Security and Pipeline: Groovy Plugins could be circumvented through methods supporting type casts and type coercion. This allowed attackers to invoke constructors for arbitrary types.
External Reference:
https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1353
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003041?
CVE-2019-1003041 has a medium severity rating due to its potential to allow arbitrary constructor invocation in Jenkins scripts.
How do I fix CVE-2019-1003041?
To remediate CVE-2019-1003041, upgrade to Jenkins Pipeline: Groovy Plugin version 2.65 or later.
What versions are affected by CVE-2019-1003041?
CVE-2019-1003041 affects Jenkins Pipeline: Groovy Plugin versions 2.64 and earlier.
Can CVE-2019-1003041 lead to remote code execution?
Yes, CVE-2019-1003041 can be exploited to execute arbitrary code within the sandbox environment.
What software components are impacted by CVE-2019-1003041?
CVE-2019-1003041 impacts Jenkins Pipeline: Groovy Plugin and Red Hat OpenShift Container Platform version 3.11.