Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Remediation
References
Related Vulnerabilities
PHP Out-of-bounds Read Vulnerability (CVE-2018-20783)
Perl Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1487)
WordPress Plugin Login as User or Customer Cross-Site Request Forgery (1.9)
LimeSurvey Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2025-41074)