Red Hat Bugzilla – Bug 1549542
CVE-2018-1000114 jenkins-plugin-promoted-builds: Promoted Builds Plugin allowed unauthorized users to run some promotion processes (SECURITY-746)
Last modified: 2018-06-29 18:34:09 EDT
Users with Job/Read access were able to approve and re-execute promotion processes with a manual promotion condition that did not specify a list of users allowed to manually approve the promotion. External References: https://jenkins.io/security/advisory/2018-02-26/