PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-1003029 Jenkins CVE debrief

CVE-2019-1003029 is a Jenkins Script Security Plugin sandbox bypass vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a defensive priority for any environment running Jenkins with this plugin installed. The supplied official records do not include deeper technical details or a CVSS score, so the safest response is to treat affected instances as exposed until verified updated per vendor guidance.

Vendor
Jenkins
Product
Script Security Plugin
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-04-25
Original CVE updated
2022-04-25
Advisory published
2022-04-25
Advisory updated
2022-04-25

Who should care

Jenkins administrators, DevOps and platform teams, security operations staff, and anyone responsible for Jenkins instances using the Script Security Plugin.

Technical summary

The official record identifies the issue as a sandbox bypass in the Jenkins Script Security Plugin. The CISA KEV entry confirms it is a known exploited vulnerability and points defenders to apply updates per vendor instructions. No additional technical detail or score is provided in the supplied corpus.

Defensive priority

High

Recommended defensive actions

  • Identify all Jenkins instances that use the Script Security Plugin.
  • Apply updates per vendor instructions as soon as possible.
  • Confirm the plugin and Jenkins instances are at the vendor-recommended fixed level.
  • Monitor Jenkins security logs and change records for unexpected script or permission-related activity.

Evidence notes

This debrief is based only on the supplied official records: the CVE record/NVD links and the CISA Known Exploited Vulnerabilities catalog entry. The corpus identifies the vulnerability as a Jenkins Script Security Plugin sandbox bypass and confirms KEV inclusion, but it does not provide a CVSS score, exploit chain details, or fixed version numbers.

Official resources

CVE published 2022-04-25 and modified 2022-04-25 in the supplied timeline. CISA added the issue to KEV on 2022-04-25 with a due date of 2022-05-16.