Description
Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to configure the plugin.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/09/23/1
https://www.jenkins.io/security/advisory/2020-09-23/#SECURITY-2004
Related Vulnerabilities
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-3795 Vulnerability in npm package semver-regex
CVE-2021-37578 Vulnerability in maven package org.apache.juddi:juddi-core
CVE-2017-3159 Vulnerability in maven package org.apache.camel:camel-snakeyaml
CVE-2021-32824 Vulnerability in maven package org.apache.dubbo:dubbo-common