ZeroHour

CVE-2016-3723

CVSS 3.0
4.3 medium
EPSS
2%p79
Published
()
Modified
Description

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.

Vendors
jenkinsredhat
Products
jenkins, openshift
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.