Description
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-0449)
MySQL CVE-2014-4238 Vulnerability (CVE-2014-4238)
WordPress Plugin Contact Form Multi by BestWebSoft Cross-Site Scripting (1.2.0)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2019-11039)
WordPress Plugin White Label CMS Cross-Site Scripting (1.5.2)