Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-oslo-concurrencyUpgrade conmonUpgrade python-oslo-logUpgrade python-kubernetesUpgrade python-debtcollectorUpgrade atomic-openshift-service-idlerUpgrade machine-config-daemonUpgrade openstack-ironic-inspectorUpgrade runcUpgrade python-oslo-serializationUpgrade ovn2.13Upgrade python-jsonschemaUpgrade python-sushyUpgrade rteval-loadsUpgrade coreos-installerUpgrade openstack-ironicUpgrade redhat-release-coreosUpgrade python-sushy-oem-idracUpgrade python-openstacksdkUpgrade ostreeUpgrade python-openshiftUpgrade cri-toolsUpgrade python-oslo-contextUpgrade podmanUpgrade openshiftUpgrade python-oslo-utilsUpgrade rust-afterburnUpgrade openstack-ironic-python-agentUpgrade butaneUpgrade console-login-helper-messagesUpgrade python-ironic-libUpgrade python-ironic-prometheus-exporterUpgrade openshift-ansibleUpgrade jenkinsUpgrade python-hardwareUpgrade python-oslo-dbUpgrade python-oslo-i18nUpgrade python-toozUpgrade haproxyUpgrade openshift-kuryrUpgrade cri-oUpgrade jenkins-2-pluginsUpgrade python-oslo-policyUpgrade python-oslo-serviceUpgrade python-pyrsistentUpgrade ironic-imagesUpgrade python-oslo-configUpgrade kata-containersUpgrade ignitionUpgrade ironic-images-ipa-x86_64Upgrade openshift-clientsUpgrade openvswitch2.15Upgrade python-oslo-upgradecheckUpgrade python-eventletUpgrade python-stevedoreUpgrade toolboxUpgrade ironic-images-ipa-ppc64leUpgrade python-keystoneauth1 | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub