Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
Jenkins 2.300, LTS 2.289.2 requires that users have Item/Read permission for applicable types in addition to Item/Cancel permission.
As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.
{
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"nvd_published_at": "2021-06-30T17:15:00Z",
"github_reviewed": true,
"github_reviewed_at": "2022-12-16T15:22:17Z"
}