CVE-2015-5317
KEVlargeInformation Disclosure in Jenkins UI Exposes Restricted Job and Build Names
CISA: Jenkins User Interface (UI) Information Disclosure Vulnerability
CVE-2015-5317 is an information disclosure flaw (CWE-200) in the Jenkins user interface in which the "Fingerprints" pages reveal the names of jobs and builds that a given user is not authorized to access. It is triggered when an authenticated, restricted user opens the Fingerprints pages in the Jenkins web UI, where fingerprint entries leak the names of otherwise-inaccessible jobs and builds. An attacker with valid low-privileged credentials gains visibility into the names and structure of restricted projects, which is useful for reconnaissance in a multi-user Jenkins environment; no code execution is implied by the flaw description. Any multi-user Jenkins deployment that restricts job or build visibility for some users is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-05-12), indicating exploitation in the wild, though no public proof-of-concept is known, ransomware use is unknown, and EPSS estimates a 22.4% probability of exploitation within 30 days (98th percentile); CVSS is not yet scored.
What to do: Apply updates per vendor instructions, the required action in CISA's KEV catalog, by upgrading Jenkins to a current supported release per Jenkins security advisories. In the interim, restrict which users can reach the Fingerprints pages in the Jenkins UI and review job-access permissions. Because the flaw is confirmed exploited in the wild, check access logs for authenticated users querying fingerprint pages, particularly on internet-reachable Jenkins servers.
| Jenkins User Interface (UI) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
- Affected
- Jenkins Jenkins User Interface (UI)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Jenkins
- Products
- Jenkins User Interface (UI)
- Weakness
- CWE-200