CVE-2015-5321: Jenkins
Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
Affected products
- Jenkins Jenkins: up to and including 1.625.1; up to and including 1.637
- Red Hat Openshift: up to and including 3.1; version 2.0 only
Published 2015-11-25. Last modified 2026-06-17.