An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NJenkins Role Based Authorization Strategy
APPJenkins≤ 3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
Related vulnerabilities
CVE-2023-28668CRITICAL9.8PL ✓same product
Jenkins Role-Based Authorization Strategy — przyznawanie wyłączonych uprawnień
CVE-2020-2286HIGH8.8same product
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cac...
CVE-2017-1000090HIGH8.8same product
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby openi...
CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓same vendor
Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same vendor
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE