Description

The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.

Remediation

References

Related Vulnerabilities

Severity

Critical

Classification

CWE-264

Tags

Patch Vendor Advisory