CVE-2015-5325
published 2015-11-25CVE-2015-5325: Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.79%
76.1th percentile
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.625.1 | — |
| jenkins | jenkins | <= 1.637 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | <= 3.1 | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2015-11-11
vendor_jenkins·2015-11-11·CVSS 7.5
CVE-2014-3665 [HIGH] Jenkins Security Advisory 2015-11-11
Title: Jenkins Security Advisory 2015-11-11
Jenkins Security Advisory 2015-11-11
This advisory announces multiple vulnerabilities in Jenkins.
Description
Project name disclosure via fingerprints
SECURITY-153 / CVE-2015-5317
The Jenkins UI allowed users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages if those shared file fingerprints with fingerprinted files in accessible jobs.
Public value used for CSRF protection salt
SECURITY-169 / CVE-2015-5318
The salt used to generate the CSRF protection tokens was a publicly accessible value, allowing malicious users to circumvent CSRF protection by generating the correct token.
XXE injection into job configurations via CLI
SECURITY-173 / CVE-20
Red Hat
jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
vendor_redhat·2015-11-11·CVSS 6.8
CVE-2015-5325 [MEDIUM] jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
OSV
Jenkins allows Bypass of Access Restrictions
osv·2022-05-13·CVSS 6.8
CVE-2015-5325 [MEDIUM] Jenkins allows Bypass of Access Restrictions
Jenkins allows Bypass of Access Restrictions
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
GHSA
Jenkins allows Bypass of Access Restrictions
ghsa·2022-05-13·CVSS 6.8
CVE-2015-5325 [MEDIUM] CWE-284 Jenkins allows Bypass of Access Restrictions
Jenkins allows Bypass of Access Restrictions
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
bugzilla·2015-11-16·CVSS 6.8
CVE-2015-5325 [MEDIUM] CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
The following flaw was found in Jenkins:
Slaves connecting via JNLP were not subject to the optional slave-to-master access control documented at http://jenkins-ci.org/security-144 (CVE-2014-3665).
This flaw allows to circumvent the major protection against less trusted node admins.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Discussion:
Fixed in Fedora in:
jenkins-1.609.3-3.fc22
jenkins-1.625.2-2.fc23
jenkins-1.625.2-2.fc24
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.1
Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070
---
This issue has been address
Bugzilla
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
bugzilla·2015-10-22·CVSS 7.5
CVE-2011-5325 [HIGH] CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
A path traversal vulnerability was found in Busybox implementation of tar. tar will extract a symlink that points outside of the current working directory and then follow that symlink when extracting other files. This allows for a directory traversal attack when extracting untrusted tarballs.
Reproducer:
http://git.busybox.net/busybox/commit/?id=a116552869db5e7793ae10968eb3c962c69b3d8c
CVE assignment:
http://seclists.org/oss-sec/2015/q4/121
Discussion:
Created busybox tracking bugs for this issue:
Affects: fedora-all [bug 1274227]
---
Upstream bug:
https://bugs.busybox.net/8411
---
The busybox packages are shipped in Red Hat Enterprise Linux 6 and earlier. However, they have a rather narrow use case
http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
2015-11-25
Published