Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Dotci | Jenkins | * | 2.40.00 (including) |
References