PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-1003029 Jenkins CVE debrief

CVE-2019-1003029 is a Jenkins Script Security Plugin sandbox bypass vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a defensive priority for any environment running Jenkins with this plugin installed. The supplied official records do not include deeper technical details or a CVSS score, so the safest response is to treat affected instances as exposed until verified updated per vendor guidance.

Vendor
Jenkins
Product
Script Security Plugin
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-04-25
Original CVE updated
2022-04-25
Advisory published
2022-04-25
Advisory updated
2022-04-25

Who should care

Jenkins administrators, DevOps and platform teams, security operations staff, and anyone responsible for Jenkins instances using the Script Security Plugin.

Technical summary

The official record identifies the issue as a sandbox bypass in the Jenkins Script Security Plugin. The CISA KEV entry confirms it is a known exploited vulnerability and points defenders to apply updates per vendor instructions. No additional technical detail or score is provided in the supplied corpus.

Defensive priority

High

Recommended defensive actions

  • Identify all Jenkins instances that use the Script Security Plugin.
  • Apply updates per vendor instructions as soon as possible.
  • Confirm the plugin and Jenkins instances are at the vendor-recommended fixed level.
  • Monitor Jenkins security logs and change records for unexpected script or permission-related activity.

Evidence notes

This debrief is based only on the supplied official records: the CVE record/NVD links and the CISA Known Exploited Vulnerabilities catalog entry. The corpus identifies the vulnerability as a Jenkins Script Security Plugin sandbox bypass and confirms KEV inclusion, but it does not provide a CVSS score, exploit chain details, or fixed version numbers.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-1003029 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-1003029

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-1003029 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1003029

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.