Description
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21198 Vulnerability (CVE-2024-21198)
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2196)
Joomla! Core 2.5.x Denial of Service (2.5.0 - 2.5.9)
Chamilo Deserialization of Untrusted Data Vulnerability (CVE-2025-50198)