Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Dec 10, 2025 | Oct 31, 2014 |
| Jenkins 2014 10 30 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 1.580.1Upgrade Jenkins to version 1.587 | Jan 21, 2019 | Nov 25, 2015 |
| Jenkins 2015 11 11 | — | Upgrade Jenkins LTS to version 1.625.2Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 1.638Upgrade Jenkins to the latest version | Jul 23, 2026 | Nov 25, 2015 |
| Jenkins 2015 11 11_cve 2015 5325 | — | — | Nov 13, 2017 | Nov 25, 2015 |
| Redhat Openshift | — | Upgrade jenkinsUpgrade jenkins-plugin-openshiftUpgrade openshift-origin-cartridge-jenkins | Oct 8, 2019 | Oct 30, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub