Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
http://www.securityfocus.com/bid/95949
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://jenkins.io/security/advisory/2017-02-01/
Related Vulnerabilities
CVE-2016-10583 Vulnerability in npm package closure-util
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.10
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:server-storage-plugin
CVE-2019-10773 Vulnerability in npm package @pnpm/package-bins
CVE-2018-8008 Vulnerability in maven package org.apache.storm:storm-core