jenkins-core is vulnerable to Missing Authorization
43
Medium Risk
The Jenkins CLI build -s flow can cancel merged queue items without verifying Item/Cancel permission. An attacker with Item/Build permission can trigger a build that merges with another queue item and cancel it by interrupting the CLI wait. The fix requires Item/Cancel permission before canceling builds in this flow.
You are affected if you are using a version that falls within the vulnerable range and users with Item/Build permission can use the Jenkins CLI build -s command.
jenkins-core is vulnerable to Missing Authorization in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.