CVE-2015-5320

EUVD-2015-5291
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
redhatopenshift
𝑥
≤ 3.1
jenkinsjenkins
𝑥
≤ 1.637
jenkinsjenkins
𝑥
≤ 1.625.1
redhatopenshift
2.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jenkins
precise
ignored
trusty
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne