Description
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21193 Vulnerability (CVE-2024-21193)
MySQL CVE-2020-14760 Vulnerability (CVE-2020-14760)
WordPress Plugin Multi Plugin Installer Arbitrary File Disclosure (1.1.0)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Security Bypass (3.0.7)
WordPress Plugin A to Z Category Listing 'R' Parameter SQL Injection (1.3)