ZeroHour

CVE-2015-5317

KEVlarge

Information Disclosure in Jenkins UI Exposes Restricted Job and Build Names

CISA: Jenkins User Interface (UI) Information Disclosure Vulnerability

CVSS
EPSS
22%p98
Published
KEV added
AI analysis

CVE-2015-5317 is an information disclosure flaw (CWE-200) in the Jenkins user interface in which the "Fingerprints" pages reveal the names of jobs and builds that a given user is not authorized to access. It is triggered when an authenticated, restricted user opens the Fingerprints pages in the Jenkins web UI, where fingerprint entries leak the names of otherwise-inaccessible jobs and builds. An attacker with valid low-privileged credentials gains visibility into the names and structure of restricted projects, which is useful for reconnaissance in a multi-user Jenkins environment; no code execution is implied by the flaw description. Any multi-user Jenkins deployment that restricts job or build visibility for some users is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-05-12), indicating exploitation in the wild, though no public proof-of-concept is known, ransomware use is unknown, and EPSS estimates a 22.4% probability of exploitation within 30 days (98th percentile); CVSS is not yet scored.

What to do: Apply updates per vendor instructions, the required action in CISA's KEV catalog, by upgrading Jenkins to a current supported release per Jenkins security advisories. In the interim, restrict which users can reach the Fingerprints pages in the Jenkins UI and review job-access permissions. Because the flaw is confirmed exploited in the wild, check access logs for authenticated users querying fingerprint pages, particularly on internet-reachable Jenkins servers.

Affected
Jenkins User Interface (UI)
Estimated exposure
largetens of thousands of internet-exposed Jenkins instances out of hundreds of thousands of total installations (order of magnitude estimate) — Jenkins is one of the most widely deployed open-source CI/CD servers, with public internet scans historically showing on the order of tens of thousands of exposed instances and usage statistics indicating hundreds of thousands of active…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

CISA Known Exploited Vulnerability
Affected
Jenkins Jenkins User Interface (UI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Jenkins
Products
Jenkins User Interface (UI)
Weakness
CWE-200

In the news