PT-2016-3806 · Cloudbees+1 · Jenkins

Alex Soto Bueno

·

Published

2016-02-03

·

Updated

2022-05-13

·

CVE-2015-7539

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 1.640 Jenkins LTS versions prior to 1.625.2
Description The issue concerns the Plugins Manager in Jenkins, which does not verify checksums for plugin files. This makes it easier for attackers to execute arbitrary code via a crafted plugin, particularly in man-in-the-middle attack scenarios.
Recommendations For Jenkins versions prior to 1.640, update to version 1.640 or later. For Jenkins LTS versions prior to 1.625.2, update to version 1.625.2 or later.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7539
GHSA-X274-9M9R-FM5G
RHSA-2016:0070
RHSA-2016:0489

Affected Products

Jenkins