Junglewise Threat Intelligence

CVE-2015-5317: Jenkins discloses project names via fingerprints

CVE-2015-5317 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Technologies: Jenkins. Vendors: Jenkins, Red Hat.

Executive brief

The Fingerprints pages in Jenkins allow remote attackers to obtain sensitive job and build name information via direct requests. This information disclosure occurs because the UI fails to properly restrict access to metadata for jobs and builds that should otherwise be inaccessible to the user.

Affected products

  • Jenkins Jenkins before 1.638
  • Jenkins Jenkins LTS before 1.625.2
  • Red Hat OpenShift Enterprise 2.0, 3.1

Timeline

  • 2015-11-11: advisory: Jenkins Security Advisory 2015-11-11 published
  • 2023-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-12: disclosed