CVE-2017-2606

CVE-2017-2606

Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of items via an UnprotectedRootAction.

Source: CVE-2017-2606

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다