Versio.io

CVE-2015-1809

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 27-02-2015 01:00
Last modified: - 27-02-2015 01:00
Total changes: - 10

Description

CVE-2015-1809 jenkins: external entity injection via XPath (SECURITY-165)

Common Vulnerability Scoring System (CVSS)

AV:N/AC:M/Au:N/C:P/I:N/A:N
Low
Attack complexity
Network
Attack vector
None
Availability
Low
Confidentiality
None
Integrity
-
Privileges required
-
Scope
-
User interaction
4.3
Base score
Exploitability score
Impact score
 

Verification logic

OR
AND
product=jenkins-0 AND versionEndExcluding=1.609.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-broker-0 AND versionEndExcluding=1.16.2.10-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-broker-util-0 AND versionEndExcluding=1.36.2.2-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-diy-0 AND versionEndExcluding=1.26.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-haproxy-0 AND versionEndExcluding=1.30.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-jbosseap-0 AND versionEndExcluding=2.26.3.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-jbossews-0 AND versionEndExcluding=1.34.3.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-jenkins-0 AND versionEndExcluding=1.28.2.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-mock-0 AND versionEndExcluding=1.22.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-nodejs-0 AND versionEndExcluding=1.33.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-perl-0 AND versionEndExcluding=1.30.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-php-0 AND versionEndExcluding=1.34.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-python-0 AND versionEndExcluding=1.33.3.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-cartridge-ruby-0 AND versionEndExcluding=1.32.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-logshifter-0 AND versionEndExcluding=1.10.1.2-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=openshift-origin-node-util-0 AND versionEndExcluding=1.37.2.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rhc-0 AND versionEndExcluding=1.37.1.2-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-console-0 AND versionEndExcluding=1.35.2.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-controller-0 AND versionEndExcluding=1.37.3.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-frontend-apache-vhost-0 AND versionEndExcluding=0.12.4.2-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-gear-placement-0 AND versionEndExcluding=0.0.2.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-msg-broker-mcollective-0 AND versionEndExcluding=1.35.3.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-node-0 AND versionEndExcluding=1.37.1.1-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
AND
product=rubygem-openshift-origin-routing-daemon-0 AND versionEndExcluding=0.25.1.2-1.el6op
vendor=Red Hat Enterprise Linux AND product=openshift AND version=2.0
 

Reference

 


Keywords

REDHAT

 

CVE-2015-1809

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.