Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.2 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade podmanUpgrade python-keystoneauth1Upgrade python-oslo-utilsUpgrade python-sushy-oem-idracUpgrade python-oslo-concurrencyUpgrade python-ironic-libUpgrade atomic-openshift-service-idlerUpgrade ostreeUpgrade openshiftUpgrade python-kubernetesUpgrade rust-afterburnUpgrade python-toozUpgrade ironic-images-ipa-x86_64Upgrade python-jsonschemaUpgrade machine-config-daemonUpgrade python-oslo-logUpgrade coreos-installerUpgrade python-sushyUpgrade ovn2.13Upgrade python-oslo-configUpgrade haproxyUpgrade jenkins-2-pluginsUpgrade runcUpgrade ignitionUpgrade python-openstacksdkUpgrade python-debtcollectorUpgrade toolboxUpgrade openshift-clientsUpgrade python-oslo-contextUpgrade openshift-kuryrUpgrade jenkinsUpgrade python-openshiftUpgrade cri-toolsUpgrade cri-oUpgrade python-oslo-upgradecheckUpgrade python-oslo-dbUpgrade python-eventletUpgrade kata-containersUpgrade openstack-ironicUpgrade openstack-ironic-python-agentUpgrade python-pyrsistentUpgrade python-oslo-i18nUpgrade ironic-images-ipa-ppc64leUpgrade rteval-loadsUpgrade butaneUpgrade conmonUpgrade openstack-ironic-inspectorUpgrade python-oslo-serviceUpgrade openshift-ansibleUpgrade ironic-imagesUpgrade python-stevedoreUpgrade redhat-release-coreosUpgrade python-oslo-serializationUpgrade console-login-helper-messagesUpgrade openvswitch2.15Upgrade python-oslo-policyUpgrade python-ironic-prometheus-exporterUpgrade python-hardware | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub