Description
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of items via an UnprotectedRootAction.
Remediation
References
Related Vulnerabilities
WordPress Plugin MPL-Publisher-Create your Ebook & Audiobook Cross-Site Scripting (1.29.1)
IBM RTC CVE-2018-1694 Vulnerability (CVE-2018-1694)
MySQL CVE-2020-2904 Vulnerability (CVE-2020-2904)
Oracle JRE CVE-2012-5071 Vulnerability (CVE-2012-5071)
Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35542)