Fedora Account System
Red Hat Associate
Red Hat Customer
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission. References: https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2278 http://www.openwall.com/lists/oss-security/2021/06/30/1
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2021:3820 https://access.redhat.com/errata/RHSA-2021:3820
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-21670