Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins LTS to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-oslo-upgradecheckUpgrade python-oslo-serviceUpgrade butaneUpgrade cri-oUpgrade toolboxUpgrade python-stevedoreUpgrade openshift-ansibleUpgrade ironic-images-ipa-ppc64leUpgrade ironic-imagesUpgrade python-eventletUpgrade haproxyUpgrade openshift-kuryrUpgrade python-keystoneauth1Upgrade python-hardwareUpgrade python-oslo-policyUpgrade python-toozUpgrade python-pyrsistentUpgrade python-oslo-i18nUpgrade openvswitch2.15Upgrade ignitionUpgrade python-oslo-dbUpgrade openshift-clientsUpgrade ironic-images-ipa-x86_64Upgrade jenkins-2-pluginsUpgrade jenkinsUpgrade python-ironic-prometheus-exporterUpgrade python-oslo-configUpgrade kata-containersUpgrade openstack-ironicUpgrade console-login-helper-messagesUpgrade redhat-release-coreosUpgrade rust-afterburnUpgrade machine-config-daemonUpgrade python-oslo-logUpgrade atomic-openshift-service-idlerUpgrade python-openstacksdkUpgrade python-kubernetesUpgrade coreos-installerUpgrade ostreeUpgrade python-ironic-libUpgrade cri-toolsUpgrade python-oslo-contextUpgrade runcUpgrade python-oslo-utilsUpgrade openstack-ironic-python-agentUpgrade python-openshiftUpgrade python-sushyUpgrade openshiftUpgrade python-debtcollectorUpgrade python-oslo-concurrencyUpgrade openstack-ironic-inspectorUpgrade python-jsonschemaUpgrade ovn2.13Upgrade conmonUpgrade python-oslo-serializationUpgrade python-sushy-oem-idracUpgrade podmanUpgrade rteval-loads | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub