Description
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-726
Related Vulnerabilities
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-ui
CVE-2018-1000142 Vulnerability in maven package org.jenkins-ci.plugins:ghprb
CVE-2008-5515 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2023-31065 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2017-5641 Vulnerability in maven package org.apache.flex.blazeds:blazeds