Skip to content

Known CVE

Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization

Jenkins Pipeline: Groovy Plugin (workflow-cps) version 2.63 and earlier contains a sandbox bypass vulnerability in CpsGroovyShell.java. During parsing, compilation, and script instantiation of CPS-transformed pipeline scripts, sandbox protections are not applied, allowing authenticated users with Overall/Read permission to execute arbitrary code on the Jenkins controller JVM.

CVE-2019-1003030

Critical2019CVSS 9.9CWE-693

cve2019 · jenkins · plugin · sandbox-bypass · rce · authenticated · kev · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website