Description
Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2061
Related Vulnerabilities
CVE-2017-1000118 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2020-2224 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2022-3143 Vulnerability in maven package org.wildfly.security:wildfly-elytron-password-impl
CVE-2023-27987 Vulnerability in maven package org.apache.linkis:linkis-computation-client
CVE-2023-34054 Vulnerability in maven package io.projectreactor.netty:reactor-netty-http