Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
http://www.securityfocus.com/bid/95949
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2599
https://github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89
https://jenkins.io/security/advisory/2017-02-01/
Related Vulnerabilities
CVE-2017-5648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-25767 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2022-41957 Vulnerability in npm package muhammara
CVE-2022-41927 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-ui
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts