Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2021-21277 Vulnerability in npm package angular-expressions
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was
CVE-2016-4468 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2023-34189 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2022-43419 Vulnerability in maven package org.jenkins-ci.plugins:katalon