Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to version 2.263.2 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-oslo-i18nUpgrade python-oslo-upgradecheckUpgrade openshift-ansibleUpgrade python-stevedoreUpgrade ironic-images-ipa-ppc64leUpgrade cri-oUpgrade python-keystoneauth1Upgrade toolboxUpgrade haproxyUpgrade kata-containersUpgrade python-eventletUpgrade python-oslo-configUpgrade python-pyrsistentUpgrade python-oslo-policyUpgrade ironic-images-ipa-x86_64Upgrade openshift-clientsUpgrade jenkins-2-pluginsUpgrade openshift-kuryrUpgrade python-oslo-serviceUpgrade python-ironic-prometheus-exporterUpgrade ironic-imagesUpgrade python-oslo-dbUpgrade python-hardwareUpgrade python-toozUpgrade openvswitch2.15Upgrade jenkinsUpgrade butaneUpgrade ignitionUpgrade machine-config-daemonUpgrade python-ironic-libUpgrade openshiftUpgrade python-debtcollectorUpgrade python-jsonschemaUpgrade redhat-release-coreosUpgrade python-sushy-oem-idracUpgrade podmanUpgrade python-oslo-logUpgrade python-oslo-contextUpgrade console-login-helper-messagesUpgrade rust-afterburnUpgrade openstack-ironic-python-agentUpgrade python-oslo-utilsUpgrade rteval-loadsUpgrade openstack-ironicUpgrade python-openstacksdkUpgrade coreos-installerUpgrade runcUpgrade python-oslo-serializationUpgrade ovn2.13Upgrade conmonUpgrade python-oslo-concurrencyUpgrade ostreeUpgrade openstack-ironic-inspectorUpgrade cri-toolsUpgrade python-kubernetesUpgrade python-openshiftUpgrade python-sushyUpgrade atomic-openshift-service-idler | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub