Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
{
"cpe": "cpe:2.3:a:jenkins:promoted_builds:*:*:*:*:*:jenkins:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.10.1"
},
{
"introduced": "867.v7c3a_b_83a_eb_79"
},
{
"fixed": "876.v99d29788b_36b_"
}
]
}