CVE-2015-5324
published 2015-11-25CVE-2015-5324: Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.06%
79.4th percentile
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.625.1 | — |
| jenkins | jenkins | <= 1.637 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | <= 3.1 | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins allows Unauthorized Viewing of Queue API Information
osv·2022-05-13
CVE-2015-5324 [MEDIUM] Jenkins allows Unauthorized Viewing of Queue API Information
Jenkins allows Unauthorized Viewing of Queue API Information
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
GHSA
Jenkins allows Unauthorized Viewing of Queue API Information
ghsa·2022-05-13
CVE-2015-5324 [MEDIUM] CWE-200 Jenkins allows Unauthorized Viewing of Queue API Information
Jenkins allows Unauthorized Viewing of Queue API Information
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
Jenkins
Jenkins Security Advisory 2015-11-11
vendor_jenkins·2015-11-11·CVSS 7.5
CVE-2014-3665 [HIGH] Jenkins Security Advisory 2015-11-11
Title: Jenkins Security Advisory 2015-11-11
Jenkins Security Advisory 2015-11-11
This advisory announces multiple vulnerabilities in Jenkins.
Description
Project name disclosure via fingerprints
SECURITY-153 / CVE-2015-5317
The Jenkins UI allowed users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages if those shared file fingerprints with fingerprinted files in accessible jobs.
Public value used for CSRF protection salt
SECURITY-169 / CVE-2015-5318
The salt used to generate the CSRF protection tokens was a publicly accessible value, allowing malicious users to circumvent CSRF protection by generating the correct token.
XXE injection into job configurations via CLI
SECURITY-173 / CVE-20
Red Hat
jenkins: Queue API did show items not visible to the current user (SECURITY-186)
vendor_redhat·2015-11-11·CVSS 5.0
CVE-2015-5324 [MEDIUM] jenkins: Queue API did show items not visible to the current user (SECURITY-186)
jenkins: Queue API did show items not visible to the current user (SECURITY-186)
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
2015-11-25
Published