Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2021-21348 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2013-6397 Vulnerability in maven package org.apache.solr:solr-core
CVE-2023-49398 Vulnerability in maven package com.jfinal:jfinal
CVE-2016-8747 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox.js