Description
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2804
Related Vulnerabilities
CVE-2020-2300 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2020-28498 Vulnerability in maven package org.webjars.npm:elliptic
CVE-2019-1003072 Vulnerability in maven package org.jenkins-ci.plugins:wildfly-deployer
CVE-2019-10755 Vulnerability in maven package org.pac4j:pac4j-saml
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind