Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Remediation
References
Related Vulnerabilities
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cross-Site Scripting (2.3.1)
WordPress Plugin Quiz And Survey Master-Best Quiz, Exam and Survey Multiple Vulnerabilities (4.7.8)
WordPress Plugin Cart66 Lite::WordPress Ecommerce Multiple Vulnerabilities (1.5.1.14)
WordPress Plugin Product Reviews Import Export for WooCommerce CSV Injection (1.4.8)