Description
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2017-10137 Vulnerability (CVE-2017-10137)
WordPress 3.0.3 KSES Library Cross-Site Scripting Vulnerability (0.6.2 - 3.0.3)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2020-1967)
WebLogic Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1324)
WordPress Plugin Role Scoper Unspecified Vulnerability (1.4.1)