CVE-2015-5317

jenkins, redhat openshift

Published 25 Nov 2015 · updated 17 Jun 2026 · Analyzed

7.5 High · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 12 May 2023, with a remediation deadline of 2 Jun 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

References