CVE-2015-5322

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openshift:2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*

History

No history.

Information

Published : 2015-11-25 20:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-5322

Mitre link : CVE-2015-5322

CVE.ORG link : CVE-2015-5322


JSON object : View

Products Affected

jenkins

  • jenkins

redhat

  • openshift
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')