The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2016-05-17T14:00:00

Updated: 2018-01-04T19:57:01

Reserved: 2016-03-30T00:00:00


Link: CVE-2016-3727

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-05-17T14:08:11.717

Modified: 2018-01-05T02:30:43.790


Link: CVE-2016-3727

JSON object: View

cve-icon Redhat Information

No data.

CWE