Description
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Remediation
References
Related Vulnerabilities
Moodle CVE-2023-5551 Vulnerability (CVE-2023-5551)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2133)
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Request Forgery (1.3.3)
WordPress Plugin ImageInject Multiple Vulnerabilities (1.15)
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)