Description
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-1737
Related Vulnerabilities
CVE-2023-24432 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2023-20883 Vulnerability in maven package org.springframework.boot:spring-boot-autoconfigure
CVE-2019-0205 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2020-12827 Vulnerability in maven package org.webjars.npm:mjml
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core