CVE-2015-7539

HIGH

Jenkins < 1.640 and LTS < 1.625.2 - Unauthenticated Arbitrary Code Execution via Plugin Checksum Bypass

Title source: llm
STIX 2.1

Description

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0489.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:0070

Scores

CVSS v3 7.5
EPSS 0.0077
EPSS Percentile 73.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (5)
jenkins/jenkins < 1.625.1
jenkins/jenkins < 1.639
org.jenkins-ci.main/jenkins-core 0 - 1.625.2Maven
redhat/openshift 2.0
redhat/openshift 3.1
Published Feb 03, 2016
Tracked Since Feb 18, 2026