Description
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
Remediation
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2005-2805)
Moodle Other Vulnerability (CVE-2004-1978)
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9)
Drupal Incorrect Authorization Vulnerability (CVE-2020-13676)
WordPress Plugin Product Catalog X Cross-Site Request Forgery (1.5.12)