Description
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
Remediation
References
https://jenkins.io/security/advisory/2018-07-18/#SECURITY-891
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2017-4973 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2023-27479 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui
CVE-2021-37580 Vulnerability in maven package org.apache.shenyu:shenyu-admin
CVE-2018-1000193 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-24709 Vulnerability in npm package @awsui/components-react