Remote API Information Disclosure in Jenkins by CloudBees
CVE-2017-2600
4.3MEDIUM
What is CVE-2017-2600?
A vulnerability in Jenkins prior to versions 2.44 and 2.32.2 allows low privilege users to access sensitive node monitor data through the remote API. This exposure can reveal critical system configuration and runtime information, posing a significant risk to system integrity and confidentiality. Users are advised to upgrade to the latest versions to mitigate this issue.
Affected Version(s)
jenkins jenkins 2.44
jenkins jenkins 2.32.2
