CyberRota Analysis
AI-GeneratedA missing permission check in the Jenkins Pipeline: Build Step Plugin allows unauthorized users to cancel downstream builds triggered by the `build` step, even if they lack the necessary Item/Cancel permission on those jobs. This vulnerability could lead to disruptions in the build process and potential denial of service for affected projects. Jenkins administrators and users of the affected plugin versions should prioritize applying updates to mitigate this risk.
Original NVD Description
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.