CVE-2015-1808
published 2015-10-16CVE-2015-1808: Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.58%
72.9th percentile
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.580.3 | — |
| jenkins | jenkins | <= 1.599 | — |
| redhat | openshift | <= 3.1 | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins Vulnerable to Denial of Service (DoS)
ghsa·2022-05-17
CVE-2015-1808 [LOW] CWE-20 Jenkins Vulnerable to Denial of Service (DoS)
Jenkins Vulnerable to Denial of Service (DoS)
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
OSV
Jenkins Vulnerable to Denial of Service (DoS)
osv·2022-05-17
CVE-2015-1808 [LOW] Jenkins Vulnerable to Denial of Service (DoS)
Jenkins Vulnerable to Denial of Service (DoS)
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
Red Hat
jenkins: update center metadata retrieval DoS attack (SECURITY-163)
vendor_redhat·2015-02-27·CVSS 3.5
CVE-2015-1808 [LOW] CWE-20 jenkins: update center metadata retrieval DoS attack (SECURITY-163)
jenkins: update center metadata retrieval DoS attack (SECURITY-163)
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
A denial of service flaw was found in the way Jenkins handled certain update center data. An authenticated user could provide specially crafted update center data to Jenkins, causing plug-in and tool installation to not work properly.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5274 OpenShift 2.2: API command injection vulnerability
bugzilla·2015-09-12·CVSS 6.5
CVE-2015-5274 [MEDIUM] CVE-2015-5274 OpenShift 2.2: API command injection vulnerability
CVE-2015-5274 OpenShift 2.2: API command injection vulnerability
It is reported that a command injection flaw exists in OpenShift's Broker API
which can lead to arbitrary code execution within the OpenShift Broker. This
issue can only be exploited by authenticated OpenShift users with access to
connect to the broker (e.g. to start cartridge and gear instances). OpenShift
version 3 is not affected.
Discussion:
This issue has been addressed in the following products:
RHEL 6 Version of OpenShift Enterprise 2.2
Via RHSA-2015:1808 https://rhn.redhat.com/errata/RHSA-2015-1808.html
Bugzilla
CVE-2015-1806 CVE-2015-1807 CVE-2015-1813 CVE-2015-1812 CVE-2015-1811 CVE-2015-1810 CVE-2015-1808 CVE-2015-1809 CVE-2015-1814 jenkins: various flaws [fedora-all]
bugzilla·2015-03-25·CVSS 6.5
CVE-2015-1806 [MEDIUM] CVE-2015-1806 CVE-2015-1807 CVE-2015-1813 CVE-2015-1812 CVE-2015-1811 CVE-2015-1810 CVE-2015-1808 CVE-2015-1809 CVE-2015-1814 jenkins: various flaws [fedora-all]
CVE-2015-1806 CVE-2015-1807 CVE-2015-1813 CVE-2015-1812 CVE-2015-1811 CVE-2015-1810 CVE-2015-1808 CVE-2015-1809 CVE-2015-1814 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2015-1808 jenkins: update center metadata retrieval DoS attack (SECURITY-163)
bugzilla·2015-03-25·CVSS 3.5
CVE-2015-1808 [LOW] CVE-2015-1808 jenkins: update center metadata retrieval DoS attack (SECURITY-163)
CVE-2015-1808 jenkins: update center metadata retrieval DoS attack (SECURITY-163)
This vulnerability allows authenticated users to disrupt the operation of Jenkins by feeding malicious update center data into Jenkins, affecting plugin installation and tool installation.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1205637]
---
jenkins-1.590-3.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
jenkins-1.606-1.fc22, jffi-1.2.7-5.fc22, jenkins-executable-war-1.29-4.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note o
http://rhn.redhat.com/errata/RHSA-2015-1844.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://bugzilla.redhat.com/show_bug.cgi?id=1205623https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27http://rhn.redhat.com/errata/RHSA-2015-1844.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://bugzilla.redhat.com/show_bug.cgi?id=1205623https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
2015-10-16
Published