VDB
CVE-2015-1806
CVE-2015-1806
PUBLISHED
CVSS 6.300000190734863 MEDIUM
Reported by redhat · Published October 16, 2015
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, *, n/a |
| Maven | org.jenkins-ci.main:jenkins-core | 1.597, 1.597 |
Timeline
- Oct 16, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- x_refsource_CONFIRM
- RHSA-2016:0070 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- RHSA-2015:1844 vendor-advisoryx_refsource_REDHAT
- https://github.com/jenkinsci/jenkins url
- https://nvd.nist.gov/vuln/detail/CVE-2015-1806 advisory
- https://github.com/advisories/GHSA-mm9c-4cv4-7rfv advisory