CVE-2016-3723
published 2016-05-17CVE-2016-3723: Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging…
PriorityP423medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.93%
77.8th percentile
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 2.2 | — |
| jenkins | jenkins | <= 1.651.1 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | rather_than_expect_all_plugin | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information in Jenkins Core
ghsa·2022-05-14
CVE-2016-3723 [MEDIUM] CWE-200 Exposure of Sensitive Information in Jenkins Core
Exposure of Sensitive Information in Jenkins Core
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
OSV
Exposure of Sensitive Information in Jenkins Core
osv·2022-05-14
CVE-2016-3723 [MEDIUM] Exposure of Sensitive Information in Jenkins Core
Exposure of Sensitive Information in Jenkins Core
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Red Hat
jenkins: Information on installed plugins exposed via API (SECURITY-250)
vendor_redhat·2016-05-11·CVSS 4.3
CVE-2016-3723 [MEDIUM] jenkins: Information on installed plugins exposed via API (SECURITY-250)
jenkins: Information on installed plugins exposed via API (SECURITY-250)
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
Jenkins
Jenkins Security Advisory 2016-05-11
vendor_jenkins·2016-05-11·CVSS 4.3
CVE-2016-3721 [MEDIUM] Jenkins Security Advisory 2016-05-11
Title: Jenkins Security Advisory 2016-05-11
Jenkins Security Advisory 2016-05-11
Revised 2016-05-12 : Added note on plugins impacted by SECURITY-170, mentioned system property disabling part of the SECURITY-243 fix.
This advisory announces multiple vulnerabilities in Jenkins.
Description
Arbitrary build parameters are passed to build scripts as environment variables
SECURITY-170 / CVE-2016-3721
Build parameters in Jenkins typically are passed to build scripts as environment variables. Some plugins allow passing arbitrary (undeclared) parameters. Depending on access permissions and installed plugins, malicious users were able to trigger builds, passing arbitrary environment variables (e.g. PATH) to modify the behavior of those build
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3723 jenkins: Information on installed plugins exposed via API (SECURITY-250)
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3723 [MEDIUM] CVE-2016-3723 jenkins: Information on installed plugins exposed via API (SECURITY-250)
CVE-2016-3723 jenkins: Information on installed plugins exposed via API (SECURITY-250)
The following flaw was found in Jenkins:
The XML/JSON API endpoints providing information about installed plugins were missing permissions checks, allowing any user with read access to Jenkins to determine which plugins and versions were installed.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1335427]
---
jenkins-1.651.2-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
jenkins-1.625.3-4.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, ple
Bugzilla
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3721 [MEDIUM] CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Checkpoint
31st October – Threat Intelligence Report
blogs_checkpoint·2022-10-31
CVE-2022-3723 31st October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US-based communications company Twilio has disclosed a new data breach that occurred on June 2022 allegedly by the same threat actors behind the August hack. The hackers have used voice phishing to trick a Twilio employee into handling over their credentials, which the hackers then used to access customer information.
Cu
http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
2016-05-17
Published