Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Remediation
References
Related Vulnerabilities
Moodle Improper Validation of Integrity Check Value Vulnerability (CVE-2012-1170)
WordPress Plugin Design Approval System Cross-Site Scripting (3.6)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3745)
WordPress Plugin WP Photo Album Plus Unspecified Vulnerability (6.5.00)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.3.4)