Improper authorization control for web services In org.jenkins-ci.main:jenkins-core
Description
Jenkins allows remote authenticated users to bypass intended restrictions and create or destroy arbitrary jobs Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.583, 1.565.3 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.