Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1806

Опубликовано: 27 фев. 2015
Источник: redhat
CVSS2: 6.5

Описание

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

It was found that the combination filter Groovy script could allow a remote attacker to potentially execute arbitrary code on a Jenkins master.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1205620jenkins: Combination filter Groovy script unsecured (SECURITY-125)

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

nvd
почти 11 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

debian
почти 11 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS b ...

github
около 4 лет назад

Jenkins allows for Privilege Escalation by Remote Authenticated Users

6.5 Medium

CVSS2