Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Remediation
References
Related Vulnerabilities
WordPress Plugin Daily Prayer Time SQL Injection (2022.02.28)
WordPress Plugin Post Thumbnail Editor Multiple Cross-Site Request Forgery Vulnerabilities (2.4.1)
Sqlite Improper Resource Shutdown or Release Vulnerability (CVE-2015-3415)
WordPress Plugin ShiftNav-Responsive Mobile Menu Cross-Site Scripting (1.7.1)
WordPress Plugin IP Blacklist Cloud Arbitrary File Disclosure (3.42)