PatchSiren cyber security CVE debrief
CVE-2019-1003029 Jenkins CVE debrief
CVE-2019-1003029 is a Jenkins Script Security Plugin sandbox bypass vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a defensive priority for any environment running Jenkins with this plugin installed. The supplied official records do not include deeper technical details or a CVSS score, so the safest response is to treat affected instances as exposed until verified updated per vendor guidance.
- Vendor
- Jenkins
- Product
- Script Security Plugin
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-04-25
- Original CVE updated
- 2022-04-25
- Advisory published
- 2022-04-25
- Advisory updated
- 2022-04-25
Who should care
Jenkins administrators, DevOps and platform teams, security operations staff, and anyone responsible for Jenkins instances using the Script Security Plugin.
Technical summary
The official record identifies the issue as a sandbox bypass in the Jenkins Script Security Plugin. The CISA KEV entry confirms it is a known exploited vulnerability and points defenders to apply updates per vendor instructions. No additional technical detail or score is provided in the supplied corpus.
Defensive priority
High
Recommended defensive actions
- Identify all Jenkins instances that use the Script Security Plugin.
- Apply updates per vendor instructions as soon as possible.
- Confirm the plugin and Jenkins instances are at the vendor-recommended fixed level.
- Monitor Jenkins security logs and change records for unexpected script or permission-related activity.
Evidence notes
This debrief is based only on the supplied official records: the CVE record/NVD links and the CISA Known Exploited Vulnerabilities catalog entry. The corpus identifies the vulnerability as a Jenkins Script Security Plugin sandbox bypass and confirms KEV inclusion, but it does not provide a CVSS score, exploit chain details, or fixed version numbers.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-1003029 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-1003029
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-1003029 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1003029
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.