Information disclosure in Jenkins - CVE-2018-1999006
Published: July 26, 2018
Jenkins
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to exposure of sensitive information in Plugin.jav. A remote attacker can determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.