cbcvebase.
CVE-2015-7537
published 2016-02-03

CVE-2015-7537: Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of…

PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.40%
82.2th percentile
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsjenkins<= 1.625.1
jenkinsjenkins<= 1.639
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinssha-1_checksums_for_the_plugin
jenkinsthis_enabled_mitm_attacks_on_the_plugin
redhatopenshift<= 3.1
redhatopenshift

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.