A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
https://github.com/katarzynamazur/cves
https://github.com/advisories/GHSA-784j-h234-m56x
https://github.com/1NTheKut/CVE-2019-1003000_RCE-DETECTION
https://github.com/0xtavian/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins
https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc
https://github.com/wetw0rk/Exploit-Development
https://jenkins.io/security/advisory/2019-01-08/#SECURITY-1266