Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Remediation
References
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5876)
WordPress Plugin WP Domain Redirect SQL Injection (1.0)
Grafana Missing Authorization Vulnerability (CVE-2023-2183)
Oracle Database Server Other Vulnerability (CVE-2001-0941)
Apache Tomcat Improper Access Control Vulnerability (CVE-2014-7810)