Improper authorization control for web services In org.jenkins-ci.main:jenkins-core

Description

Jenkins allows remote authenticated users to bypass intended restrictions and create or destroy arbitrary jobs Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions