A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.
2025-04-02T15:15:59.420
2025-04-29T14:03:21.570
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | jenkins | < 2.492.3 | Yes |
Application | jenkins | jenkins | < 2.504 | Yes |