CVE-2015-5298
published 2022-07-07CVE-2015-5298: The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.64%
46.5th percentile
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | google_login | — | — |
| jenkins | google_login | — | — |
| jenkins | google_login_plugin | — | — |
| jenkins | jenkins_instance_using_the_google_login_plugin | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2015-10-12
vendor_jenkins·2015-10-12·CVSS 6.5
CVE-2015-5298 [MEDIUM] Jenkins Security Advisory 2015-10-12
Title: Jenkins Security Advisory 2015-10-12
Jenkins Security Advisory 2015-10-12
This advisory announces a vulnerability in the Google Login Plugin .
Jenkins issue: SECURITY-208
CVE ID: CVE-2015-5298
Description
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
Severity
CVE-2015-5298 is rated medium . While the attacker will be able to successfully authenticate to any network-reachable Jenkins instance using the Google Login plugin, it will depend on the configuration of permissions, specifically the authenticated group, what the impact o
OSV
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
osv·2022-07-08
CVE-2015-5298 [MEDIUM] Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
GHSA
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
ghsa·2022-07-08
CVE-2015-5298 [MEDIUM] CWE-287 Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-07
Published