Description
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.
Remediation
References
Related Vulnerabilities
Moodle Other Vulnerability (CVE-2006-4941)
Grafana Improper Input Validation Vulnerability (CVE-2022-39306)
MySQL CVE-2020-2768 Vulnerability (CVE-2020-2768)
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9849)
WordPress Plugin IMDb Profile Widget Local File Inclusion (1.0.8)