## https://sploitus.com/exploit?id=74D24B94-E714-548E-B995-3C402292C0D2
CVE-2018-1000110: User and Node Enumeration Through Jenkins Git Plugin <v3.7
Description: An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Versions Affected: Jenkins Git plugin version 3.7.0 and earlier
Researcher: Spencer Gietzen (https://github.com/SpenGietz)
Disclosure Link: https://jenkins.io/security/advisory/2018-02-26/#SECURITY-723
NIST CVE Link: https://nvd.nist.gov/vuln/detail/CVE-2018-1000110
Proof-of-Concept Exploit:
Description: A vulnerability in the Jenkins Git plugin allows an unauthenticated user to enumerate a list of nodes and users by using the "Search" functionality, even if access is normally blocked to the "Search" function.
Usage/Exploitation: To exploit this vulnerability, include the Git plugin path in your search queries. Examples and their HTTP response codes are listed here:
https://jenkins.thewebsite.com/search/?q=x returns 403
https://jenkins.thewebsite.com/search/suggest?