Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2023-31062 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2013-4660 Vulnerability in npm package js-yaml
CVE-2014-0003 Vulnerability in maven package org.apache.camel:camel-core
CVE-2020-2184 Vulnerability in maven package org.jenkins-ci.plugins:cvs
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap