Description
Jenkins is an award-winning application that monitors executions of repeated jobs, such as building a software project or jobs run by cron.
By accessing the endpoint /securityRealm/user/admin/search/index?q= it was possible to enumerate all the Jenkins users.
Remediation
It's recommended to restrict access to this endpoint.
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-10545)
WordPress Plugin AlertWire Information Disclosure (1.1.1)
API Sensitive Info(PII) accessible without authentication
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2042)