Related Vulnerabilities: CVE-2018-1999004  

The URL that initiates agent launches on the Jenkins master before 2.133 did not perform a permission check, allowing users with Overall/Read permission to initiate agent launches. Doing so canceled all ongoing launches for the specified agent, so this allowed attackers to prevent an agent from launching indefinitely.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

The URL that initiates agent launches on the Jenkins master before 2.133 did not perform a permission check, allowing users with Overall/Read permission to initiate agent launches.
Doing so canceled all ongoing launches for the specified agent, so this allowed attackers to prevent an agent from launching indefinitely.

AVG-738 jenkins 2.132-1 2.133-1 High Fixed

21 Jul 2018 ASA-201807-14 AVG-738 jenkins High multiple issues

https://jenkins.io/security/advisory/2018-07-18/