Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
Remediation
References
Related Vulnerabilities
WordPress Plugin My Tickets Security Bypass (1.9.11)
WordPress Plugin Plugmatter Optin Feature Box Multiple SQL Injection Vulnerabilities (2.0.13)
WordPress Plugin Wordpress Membership SwiftCloud.io SQL Injection (1.0)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)