Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox
CVE-2022-43423 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2020-7652 Vulnerability in npm package snyk-broker
CVE-2019-6588 Vulnerability in maven package com.liferay:com.liferay.captcha.taglib
CVE-2020-14338 Vulnerability in maven package xerces:xercesimpl