Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2018-1000192
A information exposure vulnerability exists in Jenkins 2.120 and older LTS 2.107.2 and older in AboutJenkins.java ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.