Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openstack-ironic-inspectorUpgrade python-jsonschemaUpgrade openstack-ironicUpgrade python-openstacksdkUpgrade runcUpgrade ovn2.13Upgrade rteval-loadsUpgrade python-debtcollectorUpgrade conmonUpgrade machine-config-daemonUpgrade coreos-installerUpgrade python-oslo-concurrencyUpgrade python-sushy-oem-idracUpgrade atomic-openshift-service-idlerUpgrade python-openshiftUpgrade podmanUpgrade openstack-ironic-python-agentUpgrade python-oslo-serializationUpgrade cri-toolsUpgrade python-kubernetesUpgrade python-oslo-utilsUpgrade python-oslo-logUpgrade python-sushyUpgrade python-oslo-contextUpgrade openshiftUpgrade python-ironic-libUpgrade redhat-release-coreosUpgrade ostreeUpgrade rust-afterburnUpgrade console-login-helper-messagesUpgrade openvswitch2.15Upgrade ironic-images-ipa-x86_64Upgrade cri-oUpgrade python-oslo-dbUpgrade ignitionUpgrade openshift-clientsUpgrade jenkinsUpgrade haproxyUpgrade python-oslo-i18nUpgrade python-ironic-prometheus-exporterUpgrade ironic-imagesUpgrade python-oslo-serviceUpgrade python-toozUpgrade ironic-images-ipa-ppc64leUpgrade python-eventletUpgrade python-oslo-upgradecheckUpgrade openshift-ansibleUpgrade toolboxUpgrade python-stevedoreUpgrade python-keystoneauth1Upgrade python-oslo-policyUpgrade butaneUpgrade openshift-kuryrUpgrade jenkins-2-pluginsUpgrade kata-containersUpgrade python-oslo-configUpgrade python-hardwareUpgrade python-pyrsistent | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub