CVE-2015-5325: High severity red hat openshift vulnerability
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
Other sources
The following flaw was found in Jenkins:
Slaves connecting via JNLP were not subject to the optional slave-to-master access control documented at http://jenkins-ci.org/security-144 (CVE-2014-3665).
This flaw allows to circumvent the major protection against less trusted node admins.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5325?
CVE-2015-5325 is considered a high severity vulnerability due to its potential to allow unauthorized access to Jenkins master's resources.
How do I fix CVE-2015-5325?
To fix CVE-2015-5325, upgrade Jenkins to version 1.638 or later, or to LTS version 1.625.2 or later.
What systems are affected by CVE-2015-5325?
CVE-2015-5325 affects Jenkins versions prior to 1.638 and LTS versions before 1.625.2.
What are the consequences of exploiting CVE-2015-5325?
Exploiting CVE-2015-5325 could allow attackers to bypass access restrictions and execute unauthorized commands on the Jenkins master.
Is there a known fix for CVE-2015-5325?
Yes, the known fix for CVE-2015-5325 is to update Jenkins to a secure version that is not vulnerable.