Lucene search

K
osvGoogleOSV:GHSA-Q4WP-8C99-69PW
HistoryMay 24, 2022 - 7:06 p.m.

Improper permission checks allow canceling queue items and aborting builds in Jenkins

2022-05-2419:06:36
Google
osv.dev
13
improper permission checks
jenkins
queue items
abort builds
security issue

EPSS

0.001

Percentile

22.0%

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

Jenkins 2.300, LTS 2.289.2 requires that users have Item/Read permission for applicable types in addition to Item/Cancel permission.

As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.