Description
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2013-3789 Vulnerability (CVE-2013-3789)
WordPress 4.5.x Arbitrary File Deletion Vulnerability (4.5 - 4.5.14)
WordPress Plugin WP Featured Post with thumbnail 'src' Parameter Cross-Site Scripting (3.0)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-21338)