Description
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1773.html
https://access.redhat.com/errata/RHSA-2016:1206
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
Related Vulnerabilities
CVE-2021-26814 Vulnerability in npm package wazuh
CVE-2023-38493 Vulnerability in maven package com.linecorp.armeria:armeria
CVE-2023-3348 Vulnerability in npm package wrangler
CVE-2018-1000086 Vulnerability in npm package pym.js
CVE-2021-21638 Vulnerability in maven package org.jenkins-ci.plugins:tfs