Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
http://www.securityfocus.com/bid/95949
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://jenkins.io/security/advisory/2017-02-01/
Related Vulnerabilities
CVE-2019-10333 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2020-16041 Vulnerability in npm package electron
CVE-2016-6810 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2020-35215 Vulnerability in maven package io.atomix:atomix
CVE-2023-25766 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials