GHSA-q4wp-8c99-69pw

    Dashboard / Vulnerabilities / GHSA-q4wp-8c99-69pw

    GHSA-q4wp-8c99-69pw

    Published: 24 May 2022Last Modified: 16 Feb 2024

    Summary: Improper permission checks allow canceling queue items and aborting builds in Jenkins

    Details: Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission. Jenkins 2.300, LTS 2.289.2 requires that users have Item/Read permission for applicable types in addition to Item/Cancel permission. As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.

    Affected packages

    Package

    Name: org.jenkins-ci.main:jenkins-core

    Purl: pkg:maven/org.jenkins-ci.main/jenkins-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.289.2

    Affected versions

    1.396

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q4wp-8c99-69pw | CVE-DB