Description
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-723
Related Vulnerabilities
CVE-2021-31411 Vulnerability in maven package com.vaadin:flow-server
CVE-2023-37913 Vulnerability in maven package org.xwiki.platform:xwiki-platform-office-importer
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty.aggregate:jetty-all-server
CVE-2020-16037 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-3143 Vulnerability in maven package org.wildfly.security:wildfly-elytron-realm-ldap