CryptoMove Plugin 0.1.33 and earlier allows the configuration of an OS command to execute as part of its build step configuration. This command will be executed on the Jenkins controller as the OS user account running Jenkins, allowing user with Job/Configure permission to execute an arbitrary OS command on the Jenkins controller.
{ "nvd_published_at": "2020-03-09T16:15:00Z", "github_reviewed_at": "2023-01-05T21:09:57Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-78" ] }