CVE-2015-5317: Jenkins User Interface (UI) Information Disclosure Vulnerability
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
Other sources
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
— GitHub
The following flaw was found in Jenkins:
The Jenkins UI allowed users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages if those shared file fingerprints with fingerprinted files in accessible jobs.
Users have no control over which information they see, and the kind of information revealed is very limited.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Jenkinsto a version that resolves this vulnerability.Fixed in 1.638 - Upgrade
Upgrade
redhat/Jenkinsto a version that resolves this vulnerability.Fixed in 1.625.2 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 1.638 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 1.625.2
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5317?
CVE-2015-5317 is classified as an information disclosure vulnerability.
How do I fix CVE-2015-5317?
To remediate CVE-2015-5317, upgrade Jenkins to version 1.638 or to LTS version 1.625.2 or later.
What versions of Jenkins are affected by CVE-2015-5317?
CVE-2015-5317 affects Jenkins before version 1.638 and LTS versions before 1.625.2.
Can CVE-2015-5317 allow unauthorized job visibility?
Yes, CVE-2015-5317 allows users to see job and build names that should otherwise be inaccessible.
Is CVE-2015-5317 specific to any particular Jenkins release?
CVE-2015-5317 specifically impacts Jenkins versions prior to 1.638 and earlier LTS versions before 1.625.2.