CVE-2016-3727
published 2016-05-17CVE-2016-3727: The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the…
PriorityP422medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
2.31%
81.6th percentile
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 2.2 | — |
| jenkins | jenkins | <= 1.651.1 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | rather_than_expect_all_plugin | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins Exposes Sensitive Information via API URL
osv·2022-05-14
CVE-2016-3727 [MEDIUM] Jenkins Exposes Sensitive Information via API URL
Jenkins Exposes Sensitive Information via API URL
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
GHSA
Jenkins Exposes Sensitive Information via API URL
ghsa·2022-05-14
CVE-2016-3727 [MEDIUM] CWE-200 Jenkins Exposes Sensitive Information via API URL
Jenkins Exposes Sensitive Information via API URL
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Red Hat
jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
vendor_redhat·2016-05-11·CVSS 4.3
CVE-2016-3727 [MEDIUM] jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
Jenkins
Jenkins Security Advisory 2016-05-11
vendor_jenkins·2016-05-11·CVSS 4.3
CVE-2016-3721 [MEDIUM] Jenkins Security Advisory 2016-05-11
Title: Jenkins Security Advisory 2016-05-11
Jenkins Security Advisory 2016-05-11
Revised 2016-05-12 : Added note on plugins impacted by SECURITY-170, mentioned system property disabling part of the SECURITY-243 fix.
This advisory announces multiple vulnerabilities in Jenkins.
Description
Arbitrary build parameters are passed to build scripts as environment variables
SECURITY-170 / CVE-2016-3721
Build parameters in Jenkins typically are passed to build scripts as environment variables. Some plugins allow passing arbitrary (undeclared) parameters. Depending on access permissions and installed plugins, malicious users were able to trigger builds, passing arbitrary environment variables (e.g. PATH) to modify the behavior of those build
No detection rules found.
No public exploits indexed.
HackerOne
Outdated Jenkins server hosted at OwnCloud.org
hackerone·2017-03-30·CVSS 4.3
CVE-2016-3727 [MEDIUM] Outdated Jenkins server hosted at OwnCloud.org
Outdated Jenkins server hosted at OwnCloud.org
###Summary:
The target OwnCloud's server is running an outdated version of _Jenkins server_ which is vulnerable to various attacks.
Server Location: `https://ci.owncloud.org`
Vulnerable Software: `Jenkins ver. 2.27`
###Proof of Exploitability
CVE-2016-3727
**POC URL:** `https://ci.owncloud.org/computer/(master)/api/xml`
>Details:
> The API URL /computer/(master)/api/xml allowed users with the extended read permission for the master node to see some global Jenkins configuration, including the configuration of the security realm.
> Source: https://jenkins.io/security/advisory/2016-05-11/
Additionally, the current software version is also vulnerable to RCE.
>CVE-2017-2608
>XStream remote code execution vulnerability
>Affected Versions
Bugzilla
CVE-2016-3727 jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3727 [MEDIUM] CVE-2016-3727 jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
CVE-2016-3727 jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)
The following flaw was found in Jenkins:
The API URL /computer/(master)/api/xml allowed users with the 'extended read' permission for the master node to see some global Jenkins configuration, including the configuration of the security realm.
This URL now unconditionally sends HTTP 400 Bad Request when accessed. There is no workaround.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1335427]
---
jenkins-1.651.2-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make not
Bugzilla
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
bugzilla·2016-05-12·CVSS 4.3
CVE-2016-3721 [MEDIUM] CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
CVE-2016-3721 CVE-2016-3722 CVE-2016-3723 CVE-2016-3724 CVE-2016-3725 CVE-2016-3726 CVE-2016-3727 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11http://rhn.redhat.com/errata/RHSA-2016-1773.htmlhttps://access.redhat.com/errata/RHSA-2016:1206https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
2016-05-17
Published