Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2020-2517 Vulnerability (CVE-2020-2517)
WordPress Plugin Events Shortcodes For The Events Calendar Security Bypass (1.9.4)
Apache Tomcat Unprotected Transport of Credentials Vulnerability (CVE-2023-28708)
PostgreSQL Cryptographic Issues Vulnerability (CVE-2011-2483)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3732)