CVE-2016-0789
published 2016-04-07CVE-2016-0789: CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP…
PriorityP429medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.79%
76.1th percentile
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.642.1 | — |
| jenkins | jenkins | <= 1.649 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins: HTTP response splitting vulnerability (SECURITY-238)
vendor_redhat·2016-02-24·CVSS 6.1
CVE-2016-0789 [MEDIUM] jenkins: HTTP response splitting vulnerability (SECURITY-238)
jenkins: HTTP response splitting vulnerability (SECURITY-238)
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Jenkins
Jenkins Security Advisory 2016-02-24
vendor_jenkins·2016-02-24·CVSS 9.8
CVE-2016-0788 [CRITICAL] Jenkins Security Advisory 2016-02-24
Title: Jenkins Security Advisory 2016-02-24
Jenkins Security Advisory 2016-02-24
This advisory announces multiple vulnerabilities in Jenkins.
Description
Remote code execution vulnerability in remoting module
SECURITY-232 / CVE-2016-0788
A vulnerability in the Jenkins remoting module allowed unauthenticated remote attackers to open a JRMP listener on the server hosting the Jenkins controller process, which allowed arbitrary code execution.
HTTP response splitting vulnerability
SECURITY-238 / CVE-2016-0789
An HTTP response splitting vulnerability in the CLI command documentation allowed attackers to craft Jenkins URLs that serve malicious content.
Non-constant time comparison of API token
SECURITY-241 / CVE-2016-0790
The verifica
OSV
Jenkins has CRLF Injection Vulnerability in the CLI
osv·2022-05-14
CVE-2016-0789 [MEDIUM] Jenkins has CRLF Injection Vulnerability in the CLI
Jenkins has CRLF Injection Vulnerability in the CLI
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
GHSA
Jenkins has CRLF Injection Vulnerability in the CLI
ghsa·2022-05-14
CVE-2016-0789 [MEDIUM] CWE-113 Jenkins has CRLF Injection Vulnerability in the CLI
Jenkins has CRLF Injection Vulnerability in the CLI
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0788 CVE-2016-0789 CVE-2016-0790 CVE-2016-0791 CVE-2016-0792 jenkins: security advisory 2016-02-24 [fedora-all]
bugzilla·2016-02-25·CVSS 9.8
CVE-2016-0788 [CRITICAL] CVE-2016-0788 CVE-2016-0789 CVE-2016-0790 CVE-2016-0791 CVE-2016-0792 jenkins: security advisory 2016-02-24 [fedora-all]
CVE-2016-0788 CVE-2016-0789 CVE-2016-0790 CVE-2016-0791 CVE-2016-0792 jenkins: security advisory 2016-02-24 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
bugzilla·2016-02-25·CVSS 6.1
CVE-2016-0789 [MEDIUM] CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
The following flaw was found in Jenkins:
An HTTP response splitting vulnerability in the CLI command documentation allowed attackers to craft Jenkins URLs that serve malicious content.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.html
http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:0711https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:0711https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
2016-04-07
Published