Description
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Remediation
References
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-519
Related Vulnerabilities
CVE-2017-4973 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2018-16115 Vulnerability in maven package com.typesafe.akka:akka-actor_2.12
CVE-2023-32983 Vulnerability in maven package org.jenkins-ci.plugins:ansible
CVE-2019-10305 Vulnerability in maven package com.xebialabs.xl-deploy:jenkins-dependendencies
CVE-2014-8152 Vulnerability in maven package org.apache.santuario:xmlsec