ZeroHour

CVE-2016-3721

CVSS 3.1
4.3 medium
EPSS
2%p81
Published
()
Modified
Description

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Vendors
redhatjenkins
Products
openshift, jenkins
Weakness
CWE-17
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.