CVE-2016-3721

MEDIUM6.5EPSS 0.38%

Jenkins allows Remote Users to Inject Build Parameters

Published: 5/14/2022Modified: 3/13/2025

Description

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References (8)