CVE-2015-5317
Jenkins User Interface (UI): Information Disclosure
As of , CVE-2015-5317 in Jenkins User Interface (UI) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.
- Exploited
- Yes: CISA listed it on 12 May 2023
- US federal deadline
- 2 June 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.23Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.00 on 12 May 2023EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: www.jenkins.ioLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
CISA's description
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
The CVE record's description, from redhat
- CVE published
- 25 November 2015
- Assigned by
- redhat
- CVSS
- 7.5 High (CVSS 3.1, from CISA-ADP)
- CWE-200
- Exposure of Sensitive Information to an Unauthorized Actor
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org