Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
https://jenkins.io/security/advisory/2017-02-01/
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
http://www.securityfocus.com/bid/95949
Related Vulnerabilities
CVE-2022-46907 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2023-45280 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2017-1000394 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-5348 Vulnerability in maven package org.apache.camel:camel-jetty9
CVE-2022-23974 Vulnerability in maven package org.apache.pinot:pinot-server