CVE-2016-3727

MEDIUM

Jenkins <2.3, <1.651.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1206
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1773.html

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (5)
jenkins/jenkins < 1.651.1
jenkins/jenkins < 2.2
org.jenkins-ci.main/jenkins-core 1.652 - 2.3Maven
redhat/openshift 3.1
redhat/openshift 3.2
Published May 17, 2016
Tracked Since Feb 18, 2026