#VU21361 Improper access control in Project Inheritance - CVE-2019-10409
Published: September 26, 2019
Project Inheritance
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due a missing permission check in the HTTP endpoint triggering project creation. A remote authenticated user with Overall/Read permission can bypass implemented security restrictions and create these projects from templates.