7.5

CVE-2015-5317

Warning

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

Data is provided by the National Vulnerability Database (NVD)
JenkinsJenkins SwEdition- Version <= 1.637
JenkinsJenkins SwEditionlts Version <= 1.625.1
RedhatOpenshift Version2.0
RedhatOpenshift SwEditionenterprise Version <= 3.1

12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Jenkins User Interface (UI) Information Disclosure Vulnerability

Vulnerability

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 27.39% 0.963
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.