Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "3.10.1"
},
{
"introduced": "867.v7c3a_b_83a_eb_79"
},
{
"fixed": "876.v99d29788b_36b_"
}
]
}