PT-2015-6858 · Cloudbees+1 · Jenkins

Jesse Glick

·

Publicado

2015-11-25

·

Atualizado

2022-05-13

·

CVE-2015-5325

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 1.638 Jenkins LTS versions prior to 1.625.2
Description The issue allows attackers to bypass intended access restrictions between slaves and masters by leveraging a JNLP slave, due to an incomplete fix for a previous security issue.
Recommendations For Jenkins versions prior to 1.638, update to version 1.638 or later. For Jenkins LTS versions prior to 1.625.2, update to version 1.625.2 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5325
GHSA-X2Q2-8PWQ-FR5R
RHSA-2016:0070
RHSA-2016:0489

Produtos afetados

Jenkins