Description
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Remediation
References
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-519
Related Vulnerabilities
CVE-2020-2259 Vulnerability in maven package org.jenkins-ci.plugins:computer-queue-plugin
CVE-2021-41183 Vulnerability in maven package org.webjars:jquery-ui
CVE-2018-14042 Vulnerability in maven package org.webjars:bootstrap
CVE-2016-4567 Vulnerability in maven package org.webjars:mediaelement
CVE-2019-10285 Vulnerability in maven package org.jenkins-ci.plugins:minio-storage