Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2022-22950 Vulnerability in maven package org.springframework:spring-core
CVE-2022-43405 Vulnerability in maven package io.jenkins.plugins:pipeline-groovy-lib
CVE-2023-22894 Vulnerability in npm package @strapi/strapi
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2020-5408 Vulnerability in maven package org.springframework.security:spring-security-crypto