CVE-2015-5317
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Jenkins User Interface (UI) Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 22% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-200
מוצרים מושפעים
jenkins: jenkins; redhat: openshift
קישורים
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11… Vendor Advisory
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11… Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0489.html Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:0070 Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0489.html Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:0070 Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource