CVE-2015-5320
published 2015-11-25CVE-2015-5320: Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.08%
79.6th percentile
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.637 | — |
| jenkins | jenkins | <= 1.625.1 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | <= 3.1 | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2015-11-11
vendor_jenkins·2015-11-11·CVSS 7.5
CVE-2014-3665 [HIGH] Jenkins Security Advisory 2015-11-11
Title: Jenkins Security Advisory 2015-11-11
Jenkins Security Advisory 2015-11-11
This advisory announces multiple vulnerabilities in Jenkins.
Description
Project name disclosure via fingerprints
SECURITY-153 / CVE-2015-5317
The Jenkins UI allowed users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages if those shared file fingerprints with fingerprinted files in accessible jobs.
Public value used for CSRF protection salt
SECURITY-169 / CVE-2015-5318
The salt used to generate the CSRF protection tokens was a publicly accessible value, allowing malicious users to circumvent CSRF protection by generating the correct token.
XXE injection into job configurations via CLI
SECURITY-173 / CVE-20
Red Hat
jenkins: Secret key not verified when connecting a slave (SECURITY-184)
vendor_redhat·2015-11-11·CVSS 5.0
CVE-2015-5320 [MEDIUM] jenkins: Secret key not verified when connecting a slave (SECURITY-184)
jenkins: Secret key not verified when connecting a slave (SECURITY-184)
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
GHSA
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
ghsa·2022-05-13
CVE-2015-5320 [MEDIUM] CWE-200 Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
OSV
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
osv·2022-05-13
CVE-2015-5320 [MEDIUM] Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5320 jenkins: Secret key not verified when connecting a slave (SECURITY-184)
bugzilla·2015-11-16·CVSS 5.0
CVE-2015-5320 [MEDIUM] CVE-2015-5320 jenkins: Secret key not verified when connecting a slave (SECURITY-184)
CVE-2015-5320 jenkins: Secret key not verified when connecting a slave (SECURITY-184)
The following flaw was found in Jenkins:
JNLP slave connections did not verify that the correct secret was supplied, which allowed malicious users to connect their own machines as slaves to Jenkins knowing only the name of the slave. This enables attackers to take over Jenkins (unless the slave-to-master security subsystem is enabled) or gain access to private data like keys and source code.
This issue allowos for several different attacks, compromising integrity, stability and confidentiality.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Discussion:
Fixed in Fedora in:
jenkins-1.609.3-3.fc22
jenkins-1.625.2-2.fc23
jenkins-1.625.2-2.fc24
-
Bugzilla
CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
bugzilla·2015-02-26·CVSS 6.2
CVE-2011-5320 [MEDIUM] CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
It was reported [1] that scanf and related functions are crashing due to a bug [2] in glibc.
[1]: http://seclists.org/oss-sec/2015/q1/686
[2]: https://sourceware.org/bugzilla/show_bug.cgi?id=13138
Discussion:
Statement:
This issue affects the version of glibc package as shipped with Red Hat Enterprise Linux 5 and 6. Red Hat Product Security has rated this issue as having Low security impact. A future update in Red Hat Enterprise Linux 6 may address this issue. This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 7.
Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future u
http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
2015-11-25
Published