VulnerabilityModified
CVE-2016-3724
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
MEDIUM 6.5EPSS 2.19%
Does this matter?
Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/openshift · jenkins/jenkins
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1773.html
- https://access.redhat.com/errata/RHSA-2016:1206
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11Vendor Advisory
- https://www.cloudbees.com/jenkins-security-advisory-2016-05-11Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1773.html
- https://access.redhat.com/errata/RHSA-2016:1206
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11Vendor Advisory
- https://www.cloudbees.com/jenkins-security-advisory-2016-05-11Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.