Description
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
Remediation
References
https://jenkins.io/security/advisory/2018-07-18/#SECURITY-891
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2020-17533 Vulnerability in maven package org.apache.accumulo:accumulo-core
CVE-2023-50723 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2016-0714 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-48309 Vulnerability in npm package next-auth
CVE-2018-15685 Vulnerability in maven package org.webjars.npm:electron