Description
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
Remediation
References
https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2655
Related Vulnerabilities
CVE-2017-12621 Vulnerability in maven package commons-jelly:commons-jelly
CVE-2022-31093 Vulnerability in npm package next-auth
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2015-7520 Vulnerability in maven package org.apache.wicket:wicket-core
CVE-2018-15494 Vulnerability in maven package org.webjars.bower:dojox