CVE-2015-5317

Jenkins User Interface (UI): Information Disclosure

As of , CVE-2015-5317 in Jenkins User Interface (UI) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 12 May 2023
US federal deadline
2 June 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.23Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.00 on 12 May 2023EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.jenkins.ioLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

CISA's description

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

The CVE record's description, from redhat

CVE published
25 November 2015
Assigned by
redhat
CVSS
7.5 High (CVSS 3.1, from CISA-ADP)
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Read further