Description
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-724
Related Vulnerabilities
CVE-2014-2858 Vulnerability in maven package org.grails:grails-core
CVE-2023-34053 Vulnerability in maven package org.springframework:spring-web
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-nar-bundles
CVE-2020-2259 Vulnerability in maven package org.jenkins-ci.plugins:computer-queue-plugin
CVE-2022-36890 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework