Description
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.
Remediation
References
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2804
http://www.openwall.com/lists/oss-security/2022/11/15/4
Related Vulnerabilities
CVE-2018-6341 Vulnerability in maven package org.webjars.npm:react-dom
CVE-2023-28444 Vulnerability in npm package angular-server-side-configuration
CVE-2021-22132 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-36025 Vulnerability in maven package org.hyperledger.besu:evm
CVE-2014-8115 Vulnerability in maven package org.kie:kie-drools-wb-distribution-wars