Jenkins includes a feature that shows a JVM memory usage chart for the Jenkins controller.
Access to the chart in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier requires no permissions beyond the general Overall/Read, allowing users who are not administrators to view JVM memory usage data.
Jenkins 2.219, LTS 2.204.2 now requires Overall/Administer permissions to view the JVM memory usage chart.
{
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"github_reviewed": true,
"nvd_published_at": "2020-01-29T16:15:00Z",
"severity": "MODERATE",
"github_reviewed_at": "2022-12-19T21:13:29Z"
}