Users with Job/Read access were able to approve and re-execute promotion processes with a manual promotion condition that did not specify a list of users allowed to manually approve the promotion. External References: https://jenkins.io/security/advisory/2018-02-26/