Description
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-746
Related Vulnerabilities
CVE-2022-41226 Vulnerability in maven package com.compuware.jenkins:compuware-common-configuration
CVE-2011-2093 Vulnerability in maven package com.adobe.blazeds:flex-messaging-common
CVE-2023-41887 Vulnerability in maven package org.openrefine:database
CVE-2023-40028 Vulnerability in npm package ghost
CVE-2023-34464 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates