Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2022-39248 Vulnerability in maven package org.matrix.android:matrix-android-sdk2
CVE-2017-1000356 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10427 Vulnerability in maven package org.jenkins-ci.plugins:aqua-microscanner
CVE-2012-6662 Vulnerability in maven package org.webjars:jquery-ui
CVE-2023-29207 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates