Intelligence View
⚡ tsecurity.de Intelligence
CVE-2015-5320 | CloudBees Jenkins up to 1.637 JNLP Slave Connection information disclosure (RHSA-2016:0070 / BID-77574)
A vulnerability has been found in CloudBees Jenkins up to 1.637 and classified as critical. Affected by this vulnerability is an unknown functionality of the…
A vulnerability has been found in CloudBees Jenkins up to 1.637 and classified as critical. Affected by this vulnerability is an unknown functionality of the component JNLP Slave Connection Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2015-5320. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
This vulnerability is known as CVE-2015-5320. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Cyber Threat Intelligence & Forensik
Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
CVE-2015-5320
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
ErforderlichCompliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
BSI-Warnung (Deutschland)CVE-2015-5320
Jenkins: Mehrere Schwachstellen11.11.2015
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Web Referencewiki.jenkins-ci.org