Description
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2920
Related Vulnerabilities
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-trix
CVE-2020-13947 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2020-28460 Vulnerability in npm package multi-ini
CVE-2019-10447 Vulnerability in maven package io.jenkins.plugins:sofy-ai