Description
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.9.15)
WordPress Plugin Translate WordPress with GTranslate Cross-Site Scripting (2.8.51)
PHP CVE-2009-3559 Vulnerability (CVE-2009-3559)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1154)
WordPress Plugin LearnPress-WordPress LMS Cross-Site Scripting (4.1.3.1)