A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Requests |
Jenkins |
* |
2.2.6 (including) |
References