Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
References
Configurations
History
21 Nov 2024, 02:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2016-1773.html - | |
References | () http://www.openwall.com/lists/oss-security/2024/05/02/3 - | |
References | () https://access.redhat.com/errata/RHSA-2016:1206 - | |
References | () https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170 - Vendor Advisory | |
References | () https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11 - Vendor Advisory | |
References | () https://www.cloudbees.com/jenkins-security-advisory-2016-05-11 - Vendor Advisory |
03 Jul 2024, 01:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 4.3 |
02 May 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2016-05-17 14:08
Updated : 2024-11-21 02:50
NVD link : CVE-2016-3721
Mitre link : CVE-2016-3721
CVE.ORG link : CVE-2016-3721
JSON object : View
Products Affected
redhat
- openshift
jenkins
- jenkins
CWE
CWE-17
DEPRECATED: Code