Description
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5292 | Jenkins has Information Disclosure via Sidepanel Widget |
Github GHSA |
GHSA-4653-rmch-3g2g | Jenkins has Information Disclosure via Sidepanel Widget |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:09.341Z
Reserved: 2015-07-01T00:00:00.000Z
Link: CVE-2015-5321
No data.
Status : Modified
Published: 2015-11-25T20:59:12.447
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-5321
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA