Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin.
This vulnerability allows attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins Templating Engine Plugin 2.2 integrates with Script Security Plugin to protect its pipeline configurations.
{ "nvd_published_at": "2021-04-21T15:15:00Z", "cwe_ids": [ "CWE-693" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-12-13T19:28:15Z" }