CVE-2019-1003030
Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
9.9
CVSS 3.1
97.1 %
EPSS (current)
2022-03-25
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Jenkins / Matrix Project Plugin
Published: 2019-03-08 · Due (CISA): 2022-04-15
CWE: CWE-693 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2019/CVE-2019-1003030.yaml | Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization | – |
| exploitdb | 48904 | Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in | 2020-10-19 |
References only — no downloads or instructions.