Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
http://www.securityfocus.com/bid/95949
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://jenkins.io/security/advisory/2017-02-01/
Related Vulnerabilities
CVE-2022-29249 Vulnerability in maven package io.github.javaezlib:javaez
CVE-2020-28458 Vulnerability in maven package org.webjars.bower:datatables.net
CVE-2020-28283 Vulnerability in npm package libnested
CVE-2018-3751 Vulnerability in npm package merge-recursive
CVE-2018-20698 Vulnerability in maven package com.floragunn:search-guard-kibana-plugin