CloudBees Replication Parent 1928.1932

1 minute read

RELEASED: Public: November 13, 2024

Security advisory

Security fixes

Confidential information disclosure via aggregated node list in High Availability (HA) controllers (BEE-53014)

The High Availability (HA) controllers implemented a partial override for the REST API endpoint, listing all agents to include complete and accurate information regardless of which replica served the request. This override mistakenly permitted requests via anonymous users that in a secured controller would normally produce a 403 response code; and also served information from which job names could be deduced to users with Overall/Read access but lacking Job/Read to some jobs with builds currently running on agents managed by other replicas. Now, the permission checks match those of non-High Availability (HA) controllers.

New features

None.

Feature enhancements

None.

Resolved issues

None.

Known issues

None.

Upgrade notes

None.