Description
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Remediation
References
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-1076
Related Vulnerabilities
CVE-2017-2648 Vulnerability in maven package org.jenkins-ci.plugins:ssh-slaves
CVE-2012-1574 Vulnerability in maven package org.apache.hadoop:hadoop-mapreduce-client-core
CVE-2012-0818 Vulnerability in maven package org.jboss.resteasy:resteasy-jettison-provider
CVE-2017-5662 Vulnerability in maven package org.apache.xmlgraphics:batik-dom
CVE-2015-8859 Vulnerability in maven package org.webjars.npm:send