CVE-2015-5317

HIGH7.5⚠ KEVEPSS 39.7%

Jenkins discloses project names via fingerprints

Published: 5/13/2022Modified: 10/22/2025Added to CISA KEV: 5/12/2023

Description

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H

References (7)