Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2831 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/10/19/3 | third party advisory mailing list |