PT-2015-6858 · Cloudbees+1 · Jenkins

Jesse Glick

·

Published

2015-11-25

·

Updated

2022-05-13

·

CVE-2015-5325

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 1.638 Jenkins LTS versions prior to 1.625.2
Description The issue allows attackers to bypass intended access restrictions between slaves and masters by leveraging a JNLP slave, due to an incomplete fix for a previous security issue.
Recommendations For Jenkins versions prior to 1.638, update to version 1.638 or later. For Jenkins LTS versions prior to 1.625.2, update to version 1.625.2 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5325
GHSA-X2Q2-8PWQ-FR5R
RHSA-2016:0070
RHSA-2016:0489

Affected Products

Jenkins