First published: Wed Mar 25 2015(Updated: )
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Jenkins | <1.600 | 1.600 |
redhat/Jenkins | <1.596.1 | 1.596.1 |
Jenkins Jenkins | <=1.580.3 | |
Jenkins Jenkins | <=1.599 | |
redhat openshift | <=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1808 is classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2015-1808, upgrade Jenkins to version 1.601 or later, or to LTS version 1.596.2 or later.
CVE-2015-1808 affects remote authenticated users who can manipulate update center data.
CVE-2015-1808 allows authenticated users to disrupt the Jenkins operation by causing a denial of service.
Jenkins versions prior to 1.601 and LTS versions prior to 1.596.2 are vulnerable to CVE-2015-1808.