Description
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-807
Related Vulnerabilities
CVE-2022-38648 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge
CVE-2022-22932 Vulnerability in maven package org.apache.karaf:apache-karaf
CVE-2023-40582 Vulnerability in npm package find-exec
CVE-2016-0714 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-2128 Vulnerability in maven package com.catalogic.ecxjenkins:catalogic-ecx