CVE-2015-5320
Last modified
CVE-2015-5320 is a vulnerability of currently unknown severity. Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.. EPSS estimates a 2.06% chance of exploitation in the next 30 days.
Description
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | <= 3.1 |
| Jenkins | Jenkins | <= 1.637 |
| Jenkins | Jenkins | <= 1.625.1 |
| Redhat | Openshift | 2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5320?
How severe is CVE-2015-5320?
How do I fix CVE-2015-5320?
Are you affected by CVE-2015-5320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
