CloudBees Jenkins Platform Security Advisory 2016-07-05
This advisory announces a vulnerability in the CloudBees Template Plugin.
Failure to enforce template read permission
CJP-4615
The CloudBees Template Plugin did not prevent users without access to a specific template from creating jobs referencing that template via the API, resulting in potential exposure of secrets added to job configurations by the template transformation to users who neither have access to the template nor to other jobs based on that template.