7.5

CVE-2015-5317

Warnung

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JenkinsJenkins SwEdition- Version <= 1.637
JenkinsJenkins SwEditionlts Version <= 1.625.1
RedhatOpenshift Version2.0
RedhatOpenshift SwEditionenterprise Version <= 3.1

12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Jenkins User Interface (UI) Information Disclosure Vulnerability

Schwachstelle

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 27.39% 0.963
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.