mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 22:53:11 +00:00
1.4 KiB
1.4 KiB
CVE-2019-1003030
Description
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
POC
Reference
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/BLACKHAT-SSG/Pwn_Jenkins
- https://github.com/Cashiuus/jenkins-checkscript-rce
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/PwnAwan/Pwn_Jenkins
- https://github.com/RajChowdhury240/Secure-or-Break-Jenkins
- https://github.com/Rajchowdhury420/Secure-or-Break-Jenkins
- https://github.com/gquere/pwn_jenkins
- https://github.com/overgrowncarrot1/CVE-2019-1003030
- https://github.com/plzheheplztrying/cve_monitor
- https://github.com/retr0-13/pwn_jenkins