CVE-2016-3723

MEDIUM

Jenkins <2.3 & LTS <1.651.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1206
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1773.html

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (5)
jenkins/jenkins < 1.651.1
jenkins/jenkins < 2.2
org.jenkins-ci.main/jenkins-core 0 - 2.3Maven
redhat/openshift 3.1
redhat/openshift 3.2
Published May 17, 2016
Tracked Since Feb 18, 2026