Description
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Remediation
References
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-1076
Related Vulnerabilities
CVE-2014-0073 Vulnerability in npm package cordova-plugin-inappbrowser
CVE-2023-49379 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-28680 Vulnerability in maven package org.jenkins-ci.plugins:crap4j
CVE-2016-4468 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-syntax-xhtml