Description
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Remediation
References
Related Vulnerabilities
PostgreSQL Improper Access Control Vulnerability (CVE-2019-10127)
WordPress Plugin Akismet Cross-Site Scripting (3.1.4)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5868)
MySQL CVE-2017-3647 Vulnerability (CVE-2017-3647)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6100)