Skip to content
COOEY

EXPOSURES › CVE-2015-5317

CVE-2015-5317

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-5317 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Jenkins UI info disclosure vulnerability exposed sensitive data.

The Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to view names of jobs and builds otherwise inaccessible. This can expose sensitive data and should be patched immediately.

Shame score — Exposed sensitive data through a publicly known vulnerability, leading to potential data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.