VulnerabilityModified
CVE-2015-5298
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
MEDIUM 6.5EPSS 0.67%
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- jenkins/google login
- Source
- secalert@redhat.com
References
- http://exfiltrated.com/research-CVE-2015-5298.phpThird Party Advisory
- https://www.jenkins.io/security/advisory/2015-10-12/Vendor Advisory
- http://exfiltrated.com/research-CVE-2015-5298.phpThird Party Advisory
- https://www.jenkins.io/security/advisory/2015-10-12/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.