#VU54491 Permissions, Privileges, and Access Controls in Jenkins and Jenkins LTS - CVE-2021-21670
Published: July 1, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.