CVE Vulnerabilities

CVE-2015-5319

Published: Nov 25, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an XML-aware tool, as demonstrated by get-job and update-job.

Affected Software

NameVendorStart VersionEnd Version
OpenshiftRedhat*3.1 (including)
Red Hat OpenShift Enterprise 2.2RedHatactivemq-0:5.9.0-6.redhat.611454.el6op*
Red Hat OpenShift Enterprise 2.2RedHatjenkins-0:1.625.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-enterprise-upgrade-0:2.2.9-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-util-0:1.37.5.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-cron-0:1.25.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-haproxy-0:1.31.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mysql-0:1.31.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-php-0:1.35.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-python-0:1.34.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-msg-node-mcollective-0:1.30.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-proxy-0:1.26.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-util-0:1.38.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatphp-0:5.3.3-46.el6_7.1*
Red Hat OpenShift Enterprise 2.2RedHatrhc-0:1.38.6.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-common-0:1.29.5.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-console-0:1.35.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-controller-0:1.38.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-frontend-apache-vhost-0:0.13.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-node-0:1.38.5.3-1.el6op*
Red Hat OpenShift Enterprise 3.1RedHatatomic-openshift-0:3.1.1.6-1.git.0.b57e8bd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatheapster-0:0.18.2-3.gitaf4752e.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatjenkins-0:1.625.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-align-text-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-green-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-wrap-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-anymatch-0:1.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-array-unique-0:0.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-diff-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-flatten-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arrify-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-async-each-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-binary-extensions-0:1.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-braces-0:1.8.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-capture-stack-trace-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-chokidar-0:1.4.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-configstore-0:1.4.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-create-error-class-0:2.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-deep-extend-0:0.3.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexer-0:0.1.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexify-0:3.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-end-of-stream-0:1.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-error-ex-0:1.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-es6-promise-0:3.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-event-stream-0:3.3.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-brackets-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-range-0:1.8.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-extglob-0:0.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-filename-regex-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-fill-range-0:2.2.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-in-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-own-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-from-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-base-0:0.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-parent-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-got-0:5.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-graceful-fs-0:4.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ini-0:1.1.0-6.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-binary-path-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-dotfile-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-equal-shallow-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extendable-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extglob-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-glob-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-npm-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-number-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-isobject-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-plain-obj-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-primitive-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-redirect-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-stream-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-kind-of-0:3.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-latest-version-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lazy-cache-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.assign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.baseassign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.basecopy-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.bindcallback-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.createassigner-0:3.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.defaults-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.getnative-0:3.9.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarguments-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarray-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isiterateecall-0:3.0.9-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.keys-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.restparam-0:3.6.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lowercase-keys-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-map-stream-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-micromatch-0:2.3.5-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-mkdirp-0:0.5.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-nodemon-0:1.8.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-node-status-codes-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-normalize-path-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object-assign-0:4.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object.omit-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-optimist-0:0.4.0-5.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-osenv-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-homedir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-tmpdir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-package-json-0:2.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-glob-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-json-0:2.2.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pause-stream-0:0.0.11-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-promise-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-prepend-http-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-preserve-0:0.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ps-tree-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-randomatic-0:1.1.5-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-rc-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-read-all-stream-0:3.0.1-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-readdirp-0:2.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-regex-cache-0:0.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-registry-url-0:3.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-repeat-element-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-0:5.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-diff-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-slide-0:1.1.5-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-split-0:0.3.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-stream-combiner-0:0.2.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-string-length-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-strip-json-comments-0:1.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-success-symbol-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-through-0:2.3.4-4.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-timed-out-0:2.0.0-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-touch-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-undefsafe-0:0.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-unzip-response-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-update-notifier-0:0.6.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-url-parse-lax-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-uuid-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-write-file-atomic-0:1.1.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-xdg-basedir-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnss_wrapper-0:1.0.3-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatopenshift-ansible-0:3.0.35-1.git.0.6a386dd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatopenvswitch-0:2.4.0-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatorigin-kibana-0:0.5.0-1.el7aos*
JenkinsUbuntuprecise*
JenkinsUbuntuupstream*

References