V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-1806
DEB
Medium

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuratio…

CVSS
6.5
Medium
EPSS
0.03
p82
Published
2015-01-01
Updated
2015-01-01
Description

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

Tags · CWE
CWE-264
Affected products
Atomic-openshiftHeapsterJenkinsJenkinsJenkinsNodejs-align-textNodejs-ansi-greenNodejs-ansi-wrapNodejs-anymatchNodejs-arr-diffNodejs-arr-flattenNodejs-array-uniqueNodejs-arrifyNodejs-async-eachNodejs-binary-extensionsNodejs-bracesNodejs-capture-stack-traceNodejs-chokidarNodejs-configstoreNodejs-create-error-class
CVSS vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: S
Single
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.025 · p82
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
atomic-openshiftTracked
heapsterTracked
jenkinsTracked
jenkinsTracked
jenkinsTracked
nodejs-align-textTracked
nodejs-ansi-greenTracked
nodejs-ansi-wrapTracked
nodejs-anymatchTracked
nodejs-arr-diffTracked
nodejs-arr-flattenTracked
nodejs-array-uniqueTracked
nodejs-arrifyTracked
nodejs-async-eachTracked
nodejs-binary-extensionsTracked
nodejs-bracesTracked
nodejs-capture-stack-traceTracked
nodejs-chokidarTracked
nodejs-configstoreTracked
nodejs-create-error-classTracked
Showing first 20 of 145
Source databases
DEB
CVE
RED