cbcvebase.
CVE-2015-7539
published 2016-02-03

CVE-2015-7539: The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it…

PriorityP338high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
1.40%
69.6th percentile
The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsjenkins<= 1.639
jenkinsjenkins<= 1.625.1
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinssha-1_checksums_for_the_plugin
jenkinsthis_enabled_mitm_attacks_on_the_plugin
redhatopenshift
redhatopenshift

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.