Описание
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Дополнительная информация
Статус:
EPSS
4 Medium
CVSS2
Связанные уязвимости
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS be ...
Jenkins Exposes Sensitive Information via API URL
EPSS
4 Medium
CVSS2