MEDIUM5.3
GHSA-67v4-38h7-9jjp
Jenkins has a missing permission check, allowing users to obtain agent names
Quick fix
GHSA-67v4-38h7-9jjp — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.516.3</version> for org.jenkins-ci.main:jenkins-coreDetails
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission.
This allows attackers without Overall/Read permission to list agent names through its sidepanel executors widget.
Jenkins 2.528, LTS 2.516.3 removes the sidepanel from the affected view.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.main:jenkins-core
Introduced in:
0Fixed in: 2.516.3Fix
# pom.xml: bump <version>2.516.3</version> for org.jenkins-ci.main:jenkins-coreMaven/org.jenkins-ci.main:jenkins-core
Introduced in:
2.517Fixed in: 2.528Fix
# pom.xml: bump <version>2.528</version> for org.jenkins-ci.main:jenkins-core