Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
http://www.securityfocus.com/bid/95949
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://jenkins.io/security/advisory/2017-02-01/
Related Vulnerabilities
CVE-2020-1697 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2020-7627 Vulnerability in npm package node-key-sender
CVE-2016-10606 Vulnerability in npm package grunt-webdriver-qunit
CVE-2016-4469 Vulnerability in maven package org.apache.archiva:archiva-webapp
CVE-2019-16776 Vulnerability in maven package org.webjars.bower:npm