CVE-2016-3721

MEDIUM

Jenkins <2.3, <1.651.2 - Command Injection

Title source: llm
STIX 2.1

Description

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Scores

CVSS v3 4.3
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-17
Status published
Products (5)
jenkins/jenkins < 1.651.1
jenkins/jenkins < 2.2
org.jenkins-ci.main/jenkins-core 1.660 - 2.3Maven
redhat/openshift 3.1
redhat/openshift 3.2
Published May 17, 2016
Tracked Since Feb 18, 2026