Description
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Remediation
References
Related Vulnerabilities
Drupal Core 8.9.x Remote Code Execution (8.9.0 - 8.9.9)
WordPress Plugin Request a Quote Cross-Site Scripting (2.3.3)
Internet Information Services Other Vulnerability (CVE-2000-0778)
WebLogic CVE-2023-22108 Vulnerability (CVE-2023-22108)
WordPress Plugin WP Database Backup Cross-Site Request Forgery (4.3.5)