Description
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
Remediation
References
https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2655
Related Vulnerabilities
CVE-2018-1000148 Vulnerability in maven package org.jenkins-ci.plugins:copy-to-slave
CVE-2009-4875 Vulnerability in maven package net.fckeditor:java-core
CVE-2023-29212 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui
CVE-2022-45935 Vulnerability in maven package org.apache.james:james-server-data-file
CVE-2014-0035 Vulnerability in maven package org.apache.cxf:cxf-rt-ws-security