A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Requests | Jenkins | * | 2.2.6 (including) |
References