Description
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21129 Vulnerability (CVE-2024-21129)
WordPress Plugin WP REST API (WP API) Security Bypass (1.2.1)
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2025-61795)
MySQL CVE-2012-3158 Vulnerability (CVE-2012-3158)
WordPress Plugin Theme Demo Import Arbitrary File Upload (1.1.0)