Insufficient Permission Check Vulnerability in Jenkins (SECURITY-321)

Insufficient Permission Check Vulnerability in Jenkins (SECURITY-321)

CVE-2017-2599 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).

Learn more about our User Device Pen Test.