CVE-2019-1003007: Jenkins Warnings

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.

Affected products

  • Jenkins Warnings: up to and including 5.0.0

Published 2019-02-06. Last modified 2026-06-17.