Description
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Remediation
References
Related Vulnerabilities
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7923)
WordPress Plugin The Events Calendar Cross-Site Scripting (4.8.1)
WordPress Plugin 5gig Concerts Unspecified Vulnerability (1.0)
Oracle JRE CVE-2020-2755 Vulnerability (CVE-2020-2755)
WordPress Plugin Admin Custom Login Cross-Site Scripting (2.5.3.1)