Description
Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2170
Related Vulnerabilities
CVE-2015-8857 Vulnerability in npm package uglify-js
CVE-2023-39152 Vulnerability in maven package org.jenkins-ci.plugins:gradle
CVE-2023-4863 Vulnerability in npm package electron
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2017-5644 Vulnerability in maven package org.apache.poi:poi-ooxml