SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-1806

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

MEDIUM 6.5EPSS 2.52%

Does this matter?

Lower severity and a low EPSS score (2.52%). Track it; it rarely justifies an emergency change on its own.

Description

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.52% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
jenkins/jenkins · redhat/openshift
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.