Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3727

Опубликовано: 11 мая 2016
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1335422jenkins: Granting the permission to read node configurations allows access to overall system configuration (SECURITY-281)

EPSS

Процентиль: 28%
0.00099
Низкий

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

CVSS3: 4.3
nvd
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

CVSS3: 4.3
debian
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS be ...

CVSS3: 4.3
github
больше 3 лет назад

Jenkins Exposes Sensitive Information via API URL

EPSS

Процентиль: 28%
0.00099
Низкий

4 Medium

CVSS2