Description
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-724
Related Vulnerabilities
CVE-2018-1000404 Vulnerability in maven package com.amazonaws:aws-codebuild
CVE-2022-44729 Vulnerability in maven package org.apache.xmlgraphics:batik-svgrasterizer
CVE-2022-41244 Vulnerability in maven package org.jenkins-ci.plugins:view26
CVE-2018-11778 Vulnerability in maven package org.apache.ranger:ranger
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:github-com-protobufjs-protobuf-js