Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0789

Опубликовано: 07 апр. 2016
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 1.642.1 (включая)
Конфигурация 2
cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*
Конфигурация 3
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Версия до 1.649 (включая)

EPSS

Процентиль: 35%
0.00148
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 10 лет назад

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

redhat
почти 10 лет назад

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
debian
почти 10 лет назад

CRLF injection vulnerability in the CLI command documentation in Jenki ...

CVSS3: 6.1
github
больше 3 лет назад

Jenkins has CRLF Injection Vulnerability in the CLI

EPSS

Процентиль: 35%
0.00148
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20