Description
A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.
Remediation
References
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-1341
http://www.securityfocus.com/bid/108045
Related Vulnerabilities
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage.js
CVE-2022-27202 Vulnerability in maven package org.jenkins-ci.plugins:extended-choice-parameter
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole