Lucene search

K
cveRedhatCVE-2015-5322
HistoryNov 25, 2015 - 8:59 p.m.

CVE-2015-5322

2015-11-2520:59:13
CWE-22
redhat
web.nvd.nist.gov
45
cve-2015-5322
jenkins
directory traversal
vulnerability
nvd
security

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

71.0%

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.

Affected configurations

Nvd
Node
redhatopenshiftRange3.1enterprise
Node
redhatopenshiftMatch2.0
Node
jenkinsjenkinsRange1.637
Node
jenkinsjenkinsRange1.625.1lts
VendorProductVersionCPE
redhatopenshift*cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
redhatopenshift2.0cpe:2.3:a:redhat:openshift:2.0:*:*:*:*:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

71.0%