Description
Jenkins is an award-winning application that monitors executions of repeated jobs, such as building a software project or jobs run by cron.
By accessing the endpoint /asynchPeople it was possible to get list of the Jenkins users.
Remediation
It's recommended to restrict access to this endpoint.
References
Related Vulnerabilities
WordPress Plugin MasterStudy LMS-for Online Courses and Education Information Disclosure (3.2.10)
TorchServe Management API publicly exposed
WordPress Plugin wp superb Slideshow Information Disclosure (2.4)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15081)