Description
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1773.html
https://access.redhat.com/errata/RHSA-2016:1206
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
Related Vulnerabilities
CVE-2018-16131 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2015-1812 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-34178 Vulnerability in maven package org.jenkins-ci.plugins:embeddable-build-status
CVE-2019-10320 Vulnerability in maven package org.jenkins-ci.plugins:credentials
CVE-2017-2651 Vulnerability in maven package org.jenkins-ci.plugins:mailer