Description
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-1767
Related Vulnerabilities
CVE-2019-19040 Vulnerability in maven package org.kairosdb:kairosdb
CVE-2016-0750 Vulnerability in maven package org.infinispan:infinispan-client-hotrod
CVE-2020-2120 Vulnerability in maven package org.jenkins-ci.plugins:fitnesse
CVE-2019-16566 Vulnerability in maven package org.jenkins-ci.plugins:teamconcert
CVE-2021-21179 Vulnerability in maven package org.webjars.npm:electron