CVE-2015-5317: Jenkins User Interface (UI) Information Disclosure Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-05-12. EPSS: 23% chance of exploitation in the next 30 days.
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
Affected products
- Jenkins Jenkins: up to and including 1.637; up to and including 1.625.1
- Red Hat Openshift: version 2.0 only; up to and including 3.1
Published 2015-11-25. Last modified 2026-06-17.