Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-3721

Опубликовано: 17 мая 2016
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*
Конфигурация 2
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 1.651.1 (включая)
Конфигурация 3
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Версия до 2.2 (включая)

EPSS

Процентиль: 80%
0.02124
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-17

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 10 лет назад

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

redhat
больше 10 лет назад

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

CVSS3: 4.3
debian
больше 10 лет назад

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authentic ...

CVSS3: 6.5
github
больше 4 лет назад

Jenkins allows Remote Users to Inject Build Parameters

EPSS

Процентиль: 80%
0.02124
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-17