Description

Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.

Remediation

References

Related Vulnerabilities

Severity

Critical

Classification

CWE-264

Tags

Vendor Advisory