CVE-2015-1808: Input Validation
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
Other sources
This vulnerability allows authenticated users to disrupt the operation of Jenkins by feeding malicious update center data into Jenkins, affecting plugin installation and tool installation.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1808?
CVE-2015-1808 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2015-1808?
To fix CVE-2015-1808, upgrade Jenkins to version 1.601 or later, or to LTS version 1.596.2 or later.
What type of users are affected by CVE-2015-1808?
CVE-2015-1808 affects remote authenticated users who can manipulate update center data.
What impact does CVE-2015-1808 have on Jenkins?
CVE-2015-1808 allows authenticated users to disrupt the Jenkins operation by causing a denial of service.
Which versions of Jenkins are vulnerable to CVE-2015-1808?
Jenkins versions prior to 1.601 and LTS versions prior to 1.596.2 are vulnerable to CVE-2015-1808.