VulnerabilityAnalyzed
CVE-2015-5317
Jenkins User Interface (UI) Information Disclosure Vulnerability
KEVHIGH 7.5EPSS 22.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 22.43% probability · 98th percentile
- CISA KEV
- Listed 12 May 2023 · due 2 June 2023
- Weakness
- CWE-200
- Affected
- jenkins/jenkins · redhat/openshift
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://www.jenkins.io/security/advisory/2015-11-11/; https://nvd.nist.gov/vuln/detail/CVE-2015-5317
References
- http://rhn.redhat.com/errata/RHSA-2016-0489.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2016:0070Third Party Advisory
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0489.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2016:0070Third Party Advisory
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5317US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.