Description
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1773.html
https://access.redhat.com/errata/RHSA-2016:1206
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2012-0394 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2022-34193 Vulnerability in maven package org.lilicurroad.jenkins:packageversion
CVE-2019-10212 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js