Описание
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Уязвимые конфигурации
EPSS
4 Medium
CVSS2
Дефекты
Связанные уязвимости
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent ...
Jenkins allows Remote Users to Obtain Sensitive Information from a Plugin Code
EPSS
4 Medium
CVSS2