Description
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tom M8te Directory Traversal (1.5.3)
MySQL Other Vulnerability (CVE-2002-1809)
Joomla! Core 2.5.x Denial of Service (2.5.0 - 2.5.9)
Rukovoditel Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11815)
WordPress Plugin PG Flash Gallery Cross-Site Scripting (4.1.1)