Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7539

Опубликовано: 09 дек. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1291798jenkins: Jenkins plugin manager vulnerable to MITM attacks (SECURITY-234)

EPSS

Процентиль: 77%
0.0104
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
nvd
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
debian
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 doe ...

CVSS3: 7.5
github
больше 3 лет назад

Jenkins does not Verify Checksums for Plugin Files

EPSS

Процентиль: 77%
0.0104
Низкий

5.1 Medium

CVSS2