CVE-2021-21670: Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission. CVE-2021-21671: Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login. Please bump.
No, sorry! Please cleanup
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5b75d8eed752aa6eab438f3422f8a3a2ac3e46cb commit 5b75d8eed752aa6eab438f3422f8a3a2ac3e46cb Author: Hans de Graaff <graaff@gentoo.org> AuthorDate: 2021-07-07 08:15:48 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2021-07-07 08:31:02 +0000 dev-util/jenkins-bin: cleanup of vulnerable versions Bug: https://bugs.gentoo.org/799779 Package-Manager: Portage-3.0.20, Repoman-3.0.2 Signed-off-by: Hans de Graaff <graaff@gentoo.org> dev-util/jenkins-bin/Manifest | 2 - dev-util/jenkins-bin/jenkins-bin-2.289.1-r1.ebuild | 45 ---------------------- dev-util/jenkins-bin/jenkins-bin-2.297-r1.ebuild | 45 ---------------------- 3 files changed, 92 deletions(-)
Thanks!