A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.492.3"
},
{
"introduced": "0"
},
{
"fixed": "2.504"
}
]
}