Database/Control plane, storage & DevOps
Jenkins: Overall/Manage holders can change Appearance configuration reserved for administrators
Impact
The Appearance configuration page does not check permissions correctly, so users holding Overall/Manage can change options that are supposed to require Overall/Administer. Overall/Manage exists precisely so build operators can run the controller day to day without being administrators, and this erodes that line. The record does not enumerate which options become reachable, so judge it on what it is: a privilege-boundary defect on the controller, not a takeover. Scored 3.5, requiring an already-privileged account plus user interaction, so this is a housekeeping item rather than a reason to touch a maintenance window.
Who can reach it
A Jenkins user who already holds Overall/Manage but not Overall/Administer, working through the controller web UI. The vendor vector marks user interaction as required (UI:R), so it is not a fully self-contained action.
What to do
Affected ranges are 2.421 through 2.579 and LTS 2.426.1 through 2.568.2; the record does not name the fixed release, so take it from the Jenkins advisory of 2026-09-02 (SECURITY-3981). Upgrading the controller means restarting it and losing in-flight builds, which is the whole cost here. Given the severity and the fact that the attacker already needs a Manage-level account, fold this into your next scheduled controller upgrade rather than scheduling one for it, and in the meantime review who actually holds Overall/Manage.
References
Related entries
- IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contentsCVE-2018-1993 · IBM Spectrum Scale Local Read Only Cache (LROC)Low
- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsCVE-2019-0174 · DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issueLow
- IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailCVE-2021-29671 · IBM Spectrum Scale file audit loggingLow
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
- GitLab EE: pending members receive custom-role permissions before their membership is activeCVE-2025-9486 · GitLab EE (custom role assignment, pending membership state)Low
- Grafana: legacy correlation records can be read and permanently deleted across organizationsCVE-2026-21727 · Grafana (Correlations feature, legacy org_id = 0 records)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.