Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
References
Configurations
History
No history.
Information
Published : 2016-05-17 14:08
Updated : 2024-07-03 01:35
NVD link : CVE-2016-3721
Mitre link : CVE-2016-3721
CVE.ORG link : CVE-2016-3721
JSON object : View
Products Affected
jenkins
- jenkins
redhat
- openshift
CWE
CWE-17
DEPRECATED: Code