Description
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.
References (3)
Core 3
Core References
Patch x_refsource_confirm
https://github.com/jenkinsci/jenkins/commit/36342d71e29e0620f803a7470ce96c61761648d8
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/02/21/2
Vendor Advisory x_refsource_confirm
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-02-14
Scores
EPSS
0.0007
EPSS Percentile
21.1%
Details
CWE
CWE-264
Status
published
Products (2)
jenkins/jenkins
< 1.501
org.jenkins-ci.main/jenkins-core
1.481 - 1.502Maven
Published
Oct 17, 2014
Tracked Since
Feb 18, 2026