CISA Known Exploited Vulnerability

CVE-2019-1003030

Jenkins · Matrix Project Plugin

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

Required action

Apply updates per vendor instructions.