Description
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).
Remediation
References
Related Vulnerabilities
Zope Web Application Server Other Vulnerability (CVE-2000-1212)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-35625)
WordPress Plugin WooCommerce Cross-Site Request Forgery (2.2.2)
WordPress Plugin Commentator Cross-Site Scripting (2.5.2)
WordPress Plugin SS Downloads Multiple Cross-Site Scripting Vulnerabilities (1.4.4.1)