Vulnerability Name: | CVE-2016-3726 (CCN-113574) | ||||||||||||
Assigned: | 2016-05-17 | ||||||||||||
Published: | 2016-05-17 | ||||||||||||
Updated: | 2018-01-05 | ||||||||||||
Summary: | Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs. CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||||||||||||
CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-3726 Source: CCN Type: RHSA-2016-1206 Moderate: jenkins security update Source: CCN Type: RHSA-2016-1773 Important: Red Hat OpenShift Enterprise 2.2.10 security, bug fix, and enhancement update Source: REDHAT Type: UNKNOWN RHSA-2016:1773 Source: REDHAT Type: UNKNOWN RHSA-2016:1206 Source: XF Type: UNKNOWN jenkins-cve20163726-open-redirect(113574) Source: CONFIRM Type: Vendor Advisory https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11 Source: CCN Type: Jenkins Security Advisory 2016-05-11 Jenkins Security Advisory 2016-05-11 | CloudBees Source: CONFIRM Type: Vendor Advisory https://www.cloudbees.com/jenkins-security-advisory-2016-05-11 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-3726 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |