Red Hat Bugzilla – Bug 1418726
CVE-2017-2609 jenkins: Information disclosure vulnerability in search suggestions (SECURITY-385)
Last modified: 2018-06-29 18:18:10 EDT
The following flaw was found in Jenkins: The autocompletion for the search box provided the names of views the current user does not have access to in its suggestions. These suggestions were removed. External References: https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2017-02-01 Upstream patch: https://github.com/jenkinsci/jenkins/commit/13905d8224899ba7332fe9af4e330ea96a2ae319
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1418736]