'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2019-1003000,CVE-2019-1003001,CVE-2019-1003002: Jenkins Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2019-1003000 CVE-2019-1003001 CVE-2019-1003002
| Descripiton:
|
Cloudbees Jenkins (Hudson Labs) is a set of Java-based continuous integration tools in CLOUDBEES. This product is mainly used to monitor continuous software versions publish / test items and some timing execution tasks. Script Security Plugin is a script security plugin in it. CloudBees Script Security Plugin 2.49 and previous versions of SRC / Main / Java / ORG / JENKINSCI / PLUGINS / ScriptSecurity / Sandbox / Groovy / GroovysandBox.jav file There is a security feature problem vulnerability. This vulnerability is from security measures such as the lack of authentication, access control, authority management in a network system or product. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.