Description
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Remediation
References
Related Vulnerabilities
Varnish Cache Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0345)
phpMyFAQ Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2017-11187)
Liferay DXP Other Vulnerability (CVE-2023-33946)
Oracle Database Server CVE-2010-0851 Vulnerability (CVE-2010-0851)