CVE-2015-7539: Jenkins

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

Affected products

  • Jenkins Jenkins: up to and including 1.639; up to and including 1.625.1
  • Red Hat Openshift: version 2.0 only; version 3.1 only

Published 2016-02-03. Last modified 2026-06-17.