Lucene search

K
cveRedhatCVE-2015-1810
HistoryOct 16, 2015 - 8:59 p.m.

CVE-2015-1810

2015-10-1620:59:08
CWE-264
redhat
web.nvd.nist.gov
36
cve-2015-1810
hudsonprivatesecurityrealm class
jenkins
security vulnerability
access restriction
remote attackers
privilege escalation

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

66.3%

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the “Jenkins’ own user database” setting, which allows remote attackers to gain privileges by creating a reserved name.

Affected configurations

Nvd
Node
jenkinsjenkinsRange1.580.3lts
Node
redhatopenshiftRange3.1enterprise
Node
jenkinsjenkinsRange1.599
VendorProductVersionCPE
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
redhatopenshift*cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

66.3%