CVE-2015-1806

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*

Configuration 2 (hide)

cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2015-10-16 20:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-1806

Mitre link : CVE-2015-1806

CVE.ORG link : CVE-2015-1806


JSON object : View

Products Affected

jenkins

  • jenkins

redhat

  • openshift
CWE
CWE-264

Permissions, Privileges, and Access Controls