boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2019-1003029

Jenkins Script Security Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .7444   99.5   YES
AFFECTED
  Product                         Versions            Fixed
  Jenkins Script Security Plugin  1.53 and earlier –  —
TIMELINE
  Mar 8   Reserved by jenkins
  Mar 8   Published (CNA: jenkins)
  Apr 25  Added to CISA KEV, remediation due 2022-05-16
CNA: jenkins · CVSS v3.1 · 5 references · KEV due May 16, 2022

Description

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 8, 2019ReservedReserved by jenkins
March 8, 2019PublishedPublished (CNA: jenkins)
April 25, 2022KEV ADDEDAdded to CISA KEV, remediation due 2022-05-16

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Jenkins projectJenkins Script Security Plugin—1.53 and earlier—

References (5)

Related

Authoritative record: CVE-2019-1003029 at cve.org

Vendors: jenkins project

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-1003029 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.