CVE-2016-3725
17.05.2016, 14:08
Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption).Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 1.651.1 |
jenkins | jenkins | 𝑥 ≤ 2.2 |
redhat | openshift | 3.1 |
redhat | openshift | 3.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References