Description
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/12/13/4
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3206
Related Vulnerabilities
CVE-2023-24998 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2023-29234 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2023-27481 Vulnerability in npm package directus
CVE-2020-17510 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-web-starter
CVE-2023-33008 Vulnerability in maven package org.apache.johnzon:johnzon