Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Dec 10, 2025 | Oct 1, 2014 |
| Jenkins 2014 10 01 | — | Upgrade Jenkins LTS to version 1.565.3Upgrade Jenkins to version 1.583Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest version | Nov 13, 2017 | Oct 16, 2014 |
| Redhat Openshift | — | Upgrade atomic-openshift | Jun 18, 2018 | Oct 2, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub