Description
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2498 | Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts. |
Github GHSA |
GHSA-5532-prrf-rf5x | Arbitrary code execution vulnerability in Jenkins Speaks! Plugin |
References
| Link | Providers |
|---|---|
| https://jenkins.io/security/advisory/2017-10-11/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T22:00:40.878Z
Reserved: 2017-11-29T00:00:00.000Z
Link: CVE-2017-1000403
No data.
Status : Modified
Published: 2018-01-26T02:29:01.347
Modified: 2024-11-21T03:04:39.267
Link: CVE-2017-1000403
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA