CVE-2017-1000395: Information Exposure
(updated )
Jenkins provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api
remote API. This included Jenkins users’ email addresses if the Mailer Plugin is installed.
References
Detect and mitigate CVE-2017-1000395 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →